Primary question: Can one Apache-2.0 scanner replace separate tools for agent, MCP, skill, AI-infra, and jailbreak testing?
RepoDaily adoption score
RepoDaily rates this as 91/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.
7 source(s) across 4 source category/categories, plus a RepoDaily-specific evidence module when available.
6 workflow step(s), 5 next-action step(s), and 7 command/install signal(s) were detected.
Trending momentum is +435 stars, with maintenance/release/issue signals counted when present.
Risk is marked medium, with 5 security note(s) and 4 explicit skip condition(s).
3 opportunity lens item(s), 5 alternative(s), and 4 type-specific section(s) support differentiation.
License source or license wording is present.
6 AI/agent-related signal(s) were detected in the article text and metadata.
Project overview
Tencent/AI-Infra-Guard pitches itself as a full-stack AI red-teaming platform, and the module list backs the claim: Agent Scan for agent behavior, Skills Scan for agent skill packages, MCP scan for Model Context Protocol servers, an AI infrastructure scanner built on component fingerprints plus CVE rules, and PromptSecurity for LLM jailbreak testing. The repo pulled 435 stars in the period and sits at rank 12 on the 2026-08-22 trend list. GitHub labels the language Python, but go.mod tells a fuller story: the core is Go 1.23.2 with Python scanning modules riding alongside — the Dockerfile ships the Go binary inside a python:3.12-alpine runtime.
Release velocity is the story here. v4.5.0 (2026-07-27) open-sourced the WebUI frontend, split Agent-Scan into a standalone CLI, gave MCP-Scan dual CLI/Web operation plus a mcp-scan-lite module, and repackaged Skill-Scan as the PyPI package aig-skill-scan with SARIF 2.1.0 output. Three days later, v4.5.1 (2026-07-30) added four multi-turn jailbreak attack families — Many-Shot, PAIR, GOAT, and ActorAttack — five new OWASP agent detection skills (agentic-supply-chain, cascading-failure, human-agent-trust, inter-agent-comm, unexpected-code-execution), a web-exfiltration-detection skill, and four new MCP rules covering hardcoded secrets and insecure deserialization.
The rule database is operated like signature data: dated drops (2026-06-29, 2026-07-13, 2026-07-17, 2026-07-24) keep adding AIG rules, and v4.5.0 added CVE rules for Jan, Open WebUI, crewai, and lobehub — the exact AI components most shops now expose. Docs cite 1,700+ CVE rules, with the German and Russian READMEs corrected upward to 1,900+. Everything ships under Apache-2.0, and SECURITY.md is unusually candid about the tool's single-operator design.
Why it is trending now
- 435 stars in the window at rank 12, roughly three weeks after the back-to-back v4.5.0 (07-27) and v4.5.1 (07-30) releases.
- Four named multi-turn jailbreak attacks — Many-Shot, PAIR, GOAT, ActorAttack — landed in PromptSecurity in a single patch release, work most red teamers would otherwise script by hand.
- Skill auditing became installable: aig-skill-scan on PyPI emits SARIF 2.1.0, targeting the new attack surface of publishable agent skills.
- MCP security rules grew by six-plus in July 2026 (PRs #458 and #469 in v4.5.0, plus v4.5.1's hardcoded-secrets and insecure-deserialization rules).
- The frontend went open source in v4.5.0 with environment configuration included, turning the WebUI from a binary-embedded mystery into auditable code.
Problem it solves
- An AI deployment now spans four distinct layers — agent frameworks, MCP servers, agent skills, and AI dashboards like Open WebUI and Jan — and each layer usually demands its own scanner.
- Jailbreak methods (Many-Shot, PAIR, GOAT, ActorAttack) mostly exist as research code, not as maintained, runnable tooling.
- MCP servers carry config-level flaws — hardcoded secrets, insecure deserialization — that generic web vulnerability scanners do not test.
- Agent-specific OWASP risks such as agentic supply chain, cascading failure, and inter-agent communication have no equivalent in traditional CVE scanners.
- Findings must land in CI and defect trackers, which expect SARIF, not console logs.
How it works
- Deploy the stack: the multi-stage Dockerfile builds the frontend on node:22-alpine with pnpm, compiles the Go binary from ./cmd/cli/main.go on golang:1.23.2-alpine, and ships everything in python:3.12-alpine with agent-scan dependencies installed via `uv sync --no-dev`.
- Start the WebUI on port 8088 (default bind 127.0.0.1:8088) or stay fully offline with CLI mode: `aig -target ...` writes findings to stdout or a file with no network exposure.
- AI Infra scan matches components against data/fingerprints and data/vuln; the 1,700+ CVE rules include the July additions for Jan, Open WebUI, crewai, and lobehub.
- Agent-Scan runs detection skills registered in _DETECTION_SKILLS — including the five new OWASP skills — against the target agent, inside AIG or as its own CLI.
- MCP-Scan probes MCP servers (dual-mode CLI + AIG Web, plus mcp-scan-lite), and aig-skill-scan audits skill packages, emitting SARIF 2.1.0 for pipeline ingestion.
- PromptSecurity fires multi-turn jailbreak attacks through an operator-configured LLM API key; tasks persist in /app/db/tasks.db for the WebUI to track.
Architecture read: Go core, Python modules, one binary
- go.mod declares `go 1.23.2`; gin-gonic/gin v1.10.0 serves HTTP, gorilla/websocket v1.5.3 powers the live WebUI, gorm.io/gorm v1.26.1 with glebarez/sqlite stores tasks, and spf13/cobra v1.9.1 drives the CLI.
- The networking layer is projectdiscovery DNA — rawhttp v0.1.69, retryablehttp-go v1.0.82, fastdialer v0.2.9, hmap v0.0.62 — the same library family behind nuclei-style scanning.
- LLM integration is explicit in the dependency list: openai-go v1.8.3 for model calls and mark3labs/mcp-go v0.32.0 as the MCP client used during MCP scans.
- The Dockerfile copies the pnpm-built frontend into common/websocket/static/, so the Go binary serves the UI without a separate web server.
- Agent-Scan is Python with its own dependency set (`uv sync --no-dev` runs inside the image), which explains why GitHub classifies the repo as Python while the core binary is Go.
Deployment notes: single operator, loopback first
- Runtime base is python:3.12-alpine with bash, curl, and git added; entrypoint is /app/start.sh; EXPOSE 8088.
- SECURITY.md fixes the default WebUI bind at 127.0.0.1:8088 and states plainly that exposing `-ws-addr` beyond loopback is operator misconfiguration, not an AIG vulnerability.
- Declared volumes: /app/uploads, /app/db, /app/data, /app/logs; task storage sits at DB_PATH=/app/db/tasks.db.
- Healthcheck runs `pgrep ai-infra-guard || exit 1` every 30 seconds with a 3-second timeout.
- ENV AIG_API_CHECKER_URL=http://agent:8000 and TZ=Asia/Shanghai point to a companion service layout where an agent container handles API-key checks.
Command surface: what you actually run
- `aig -target ...` — CLI scan mode, documented in SECURITY.md with no network exposure and output to stdout/file.
- `-ws-addr` — WebUI bind address for the 8088 service.
- `--version` — required output in security reports to pin the audited build; v4.5.1 fixed version checks to bypass GitHub API rate limits via a releases/latest redirect.
- `aig-skill-scan` — the standalone PyPI package for skill auditing; its Stage 2 code audit now writes a Markdown report instead of XML.
- Agent-Scan and MCP-Scan both became standalone CLIs in v4.5.0, so each module runs independently of the main binary.
Maintenance read: cadence, fixes, and data hygiene
- Two releases in four days (v4.5.0 on 2026-07-27, v4.5.1 on 2026-07-30), each with dozens of changelog entries — fast iteration, but upgrades deserve testing.
- Community input lands: PRs #458 and #469 (MCP rules), #459 (component fingerprints), and #427 (agentic-tool-misuse dataset) shipped in v4.5.0; the fix for issue #331's frontend checkbox jumping shipped in v4.5.1.
- Rule data gets corrected, not just appended: v4.5.0 removed 4 CVE rules without matching fingerprints, fixed YAML parse errors in 4 vuln rule files, and cleaned duplicate fingerprints and directories.
- Docs exist in 9 README languages and counts drift: v4.5.1 corrected CVE counts from 1600+ to 1900+ in README_DE and README_RU.
- User acknowledgements name Tiane and Binus University, and the project syncs a Securing the AI Agent paper across READMEs — signals of real deployment, not just stars.
Who should pay attention?
Good fit if
- Security engineers auditing MCP servers before production — hardcoded-secrets and insecure-deserialization rules shipped in v4.5.1.
- Operators running Open WebUI, Jan, crewai, or lobehub, all covered by the v4.5.0 CVE rule additions.
- Red teamers who want prebuilt multi-turn jailbreak attacks (Many-Shot, PAIR, GOAT, ActorAttack) instead of hand-maintained scripts.
- Platform builders adding a skill-audit gate to a marketplace, using aig-skill-scan's SARIF 2.1.0 output in CI.
Skip for now if
- Anyone needing multi-tenant scanning with login and per-user permissions — SECURITY.md states no such system exists.
- Shops unwilling to send attack prompts to an external LLM API; PromptSecurity requires an operator-supplied API key.
- Pure network CVE scanning at scale — projectdiscovery nuclei is purpose-built for that job.
- Environments that cannot run Docker or local binaries; this repo ships no hosted service.
Risks and cautions
Apache-2.0 licensing and a fast release cadence are real strengths, but the WebUI is authless by design, jailbreak testing depends on an external LLM API key, and detection quality tracks the freshness of the rule data.
- No login, sessions, or per-user permissions in the WebUI; anyone reaching `-ws-addr` is treated as the operator, so deployments must stay on loopback or a dedicated scan host.
- The LLM API key sits in config by operator choice — SECURITY.md explicitly classifies key-in-config reports as out of scope.
- Detection depends on data/vuln and data/fingerprints freshness; the changelog shows rule corrections (duplicate removals, YAML fixes, 4 orphaned CVE rules dropped) alongside additions.
- A Go core, Python modules, and a Node frontend build make local builds heavier than single-language scanners.
- Apache-2.0 license, including the patent grant, permits commercial red-team use without royalties.
- Disclosure runs through GitHub Security Advisories with a published triage gate: exact file/function/line range, `--version` output, a PoC against latest main, and demonstrated impact; contact is [email protected].
- SECURITY.md publishes its false-positive list (prompt-injection-only chains, TLS-on-loopback claims, self-scan reports), which shortens reporter-maintainer cycles.
- Prompt injection against AIG itself is out of scope unless it crosses an OS, network, or filesystem boundary — a defensible line for a red-teaming tool.
- Recommended deployment is a local machine or dedicated scan host with the WebUI on loopback; CLI mode (`aig -target ...`) exposes no network surface at all.
Alternatives to compare
| Approach | When to use | Trade-off |
|---|---|---|
Microsoft PyRIT | You want a Python SDK to script your own LLM red-team pipelines and scoring logic rather than use a fixed scanner UI | Free, open source |
NVIDIA garak | You need a probe-style LLM vulnerability scanner and already work in Python | Free, open source |
projectdiscovery nuclei | Targets are conventional network services; AIG's go.mod already builds on projectdiscovery networking libraries | Free, open source |
mcp-scan (Invariant Labs) | You only inspect MCP servers and want a focused, lightweight checker | Free, open source |
Commercial AI security platforms | You need managed, multi-tenant scanning with SSO, audit trails, and vendor SLAs | Subscription |
What this trend reveals
Skill auditing as a marketplace gate
Skill-Scan is the newest module: added in v4.5.0, repackaged as aig-skill-scan on PyPI, simplified to a single default LLM, with Stage 2 code audit writing Markdown plus SARIF 2.1.0 output. A skill marketplace could run it before listing a package.
Install aig-skill-scan from PyPI, audit 5-10 published skills, and diff its SARIF findings against a manual review of the same packages.
MCP admission control from scanning rules
MCP rules grew fast in July 2026 — PRs #458 and #469 in v4.5.0, then hardcoded-secrets and insecure-deserialization rules in v4.5.1 — and a mcp-scan-lite module exists specifically for lighter-weight runs.
Run mcp-scan-lite against every MCP server in a staging registry, tally findings per rule, and compare with a manual config review of the same servers.
Fingerprints for the AI component layer
The v4.5.0 data drop added CVE rules for Jan, Open WebUI, crewai, and lobehub plus new AI component fingerprints (PR #459) — exactly the exposed dashboards generic scanners fingerprint poorly.
Deploy one outdated Open WebUI or Jan instance in a lab and confirm AIG identifies the component and fires the matching data/vuln rules.
RepoDaily verdict
AI-Infra-Guard is trending because it collapses five tools into one Apache-2.0 binary: agent behavior scans, MCP server checks, skill auditing, 1,700+-rule AI infra CVE scanning, and four families of multi-turn jailbreak attacks. The v4.5.x releases show serious iteration speed — a PyPI package, SARIF output, dual-mode MCP scanning, and named OWASP agent skills inside four days. Run it as a single-operator lab instrument on loopback, keep the rule data current, and skip it if you need a multi-tenant platform; the project itself says it is not one.