RepoDaily · 2026-08-22 · Security tool

Tencent AI-Infra-Guard: One Open-Source Scanner for Agents, MCP Servers, Skills, and LLM Jailbreaks

#12 Security tool Python +435 Tencent/AI-Infra-Guard Open repository

Tencent's Apache-2.0 AI red-teaming platform combines Agent Scan, Skill Scan, MCP scan, AI infra CVE checks with 1,700+ rules, and multi-turn jailbreak attacks in one tool.

Repo typeSecurity tool
Best forSecurity engineers and red teamers auditing AI agents, MCP servers, agent skill packages, and exposed AI components from one CLI or local WebUI
Risk levelMedium — authless single-operator WebUI, jailbreak modules need an external LLM API key
Time to evaluate1-2 hours (build image, scan a lab target, review findings)

Primary question: Can one Apache-2.0 scanner replace separate tools for agent, MCP, skill, AI-infra, and jailbreak testing?

91/100

RepoDaily adoption score

RepoDaily rates this as 91/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.

Directional score from RepoDaily sources and adoption notes, not a benchmark.Risk: Medium
100Evidence quality

7 source(s) across 4 source category/categories, plus a RepoDaily-specific evidence module when available.

100Installability

6 workflow step(s), 5 next-action step(s), and 7 command/install signal(s) were detected.

63Maintenance confidence

Trending momentum is +435 stars, with maintenance/release/issue signals counted when present.

93Production readiness

Risk is marked medium, with 5 security note(s) and 4 explicit skip condition(s).

100Differentiation

3 opportunity lens item(s), 5 alternative(s), and 4 type-specific section(s) support differentiation.

82License clarity

License source or license wording is present.

84Agent / AI fit

6 AI/agent-related signal(s) were detected in the article text and metadata.

Project overview

Tencent/AI-Infra-Guard pitches itself as a full-stack AI red-teaming platform, and the module list backs the claim: Agent Scan for agent behavior, Skills Scan for agent skill packages, MCP scan for Model Context Protocol servers, an AI infrastructure scanner built on component fingerprints plus CVE rules, and PromptSecurity for LLM jailbreak testing. The repo pulled 435 stars in the period and sits at rank 12 on the 2026-08-22 trend list. GitHub labels the language Python, but go.mod tells a fuller story: the core is Go 1.23.2 with Python scanning modules riding alongside — the Dockerfile ships the Go binary inside a python:3.12-alpine runtime.

Release velocity is the story here. v4.5.0 (2026-07-27) open-sourced the WebUI frontend, split Agent-Scan into a standalone CLI, gave MCP-Scan dual CLI/Web operation plus a mcp-scan-lite module, and repackaged Skill-Scan as the PyPI package aig-skill-scan with SARIF 2.1.0 output. Three days later, v4.5.1 (2026-07-30) added four multi-turn jailbreak attack families — Many-Shot, PAIR, GOAT, and ActorAttack — five new OWASP agent detection skills (agentic-supply-chain, cascading-failure, human-agent-trust, inter-agent-comm, unexpected-code-execution), a web-exfiltration-detection skill, and four new MCP rules covering hardcoded secrets and insecure deserialization.

The rule database is operated like signature data: dated drops (2026-06-29, 2026-07-13, 2026-07-17, 2026-07-24) keep adding AIG rules, and v4.5.0 added CVE rules for Jan, Open WebUI, crewai, and lobehub — the exact AI components most shops now expose. Docs cite 1,700+ CVE rules, with the German and Russian READMEs corrected upward to 1,900+. Everything ships under Apache-2.0, and SECURITY.md is unusually candid about the tool's single-operator design.

Problem it solves

  • An AI deployment now spans four distinct layers — agent frameworks, MCP servers, agent skills, and AI dashboards like Open WebUI and Jan — and each layer usually demands its own scanner.
  • Jailbreak methods (Many-Shot, PAIR, GOAT, ActorAttack) mostly exist as research code, not as maintained, runnable tooling.
  • MCP servers carry config-level flaws — hardcoded secrets, insecure deserialization — that generic web vulnerability scanners do not test.
  • Agent-specific OWASP risks such as agentic supply chain, cascading failure, and inter-agent communication have no equivalent in traditional CVE scanners.
  • Findings must land in CI and defect trackers, which expect SARIF, not console logs.

How it works

  1. Deploy the stack: the multi-stage Dockerfile builds the frontend on node:22-alpine with pnpm, compiles the Go binary from ./cmd/cli/main.go on golang:1.23.2-alpine, and ships everything in python:3.12-alpine with agent-scan dependencies installed via `uv sync --no-dev`.
  2. Start the WebUI on port 8088 (default bind 127.0.0.1:8088) or stay fully offline with CLI mode: `aig -target ...` writes findings to stdout or a file with no network exposure.
  3. AI Infra scan matches components against data/fingerprints and data/vuln; the 1,700+ CVE rules include the July additions for Jan, Open WebUI, crewai, and lobehub.
  4. Agent-Scan runs detection skills registered in _DETECTION_SKILLS — including the five new OWASP skills — against the target agent, inside AIG or as its own CLI.
  5. MCP-Scan probes MCP servers (dual-mode CLI + AIG Web, plus mcp-scan-lite), and aig-skill-scan audits skill packages, emitting SARIF 2.1.0 for pipeline ingestion.
  6. PromptSecurity fires multi-turn jailbreak attacks through an operator-configured LLM API key; tasks persist in /app/db/tasks.db for the WebUI to track.

Architecture read: Go core, Python modules, one binary

  • go.mod declares `go 1.23.2`; gin-gonic/gin v1.10.0 serves HTTP, gorilla/websocket v1.5.3 powers the live WebUI, gorm.io/gorm v1.26.1 with glebarez/sqlite stores tasks, and spf13/cobra v1.9.1 drives the CLI.
  • The networking layer is projectdiscovery DNA — rawhttp v0.1.69, retryablehttp-go v1.0.82, fastdialer v0.2.9, hmap v0.0.62 — the same library family behind nuclei-style scanning.
  • LLM integration is explicit in the dependency list: openai-go v1.8.3 for model calls and mark3labs/mcp-go v0.32.0 as the MCP client used during MCP scans.
  • The Dockerfile copies the pnpm-built frontend into common/websocket/static/, so the Go binary serves the UI without a separate web server.
  • Agent-Scan is Python with its own dependency set (`uv sync --no-dev` runs inside the image), which explains why GitHub classifies the repo as Python while the core binary is Go.

Deployment notes: single operator, loopback first

  • Runtime base is python:3.12-alpine with bash, curl, and git added; entrypoint is /app/start.sh; EXPOSE 8088.
  • SECURITY.md fixes the default WebUI bind at 127.0.0.1:8088 and states plainly that exposing `-ws-addr` beyond loopback is operator misconfiguration, not an AIG vulnerability.
  • Declared volumes: /app/uploads, /app/db, /app/data, /app/logs; task storage sits at DB_PATH=/app/db/tasks.db.
  • Healthcheck runs `pgrep ai-infra-guard || exit 1` every 30 seconds with a 3-second timeout.
  • ENV AIG_API_CHECKER_URL=http://agent:8000 and TZ=Asia/Shanghai point to a companion service layout where an agent container handles API-key checks.

Command surface: what you actually run

  • `aig -target ...` — CLI scan mode, documented in SECURITY.md with no network exposure and output to stdout/file.
  • `-ws-addr` — WebUI bind address for the 8088 service.
  • `--version` — required output in security reports to pin the audited build; v4.5.1 fixed version checks to bypass GitHub API rate limits via a releases/latest redirect.
  • `aig-skill-scan` — the standalone PyPI package for skill auditing; its Stage 2 code audit now writes a Markdown report instead of XML.
  • Agent-Scan and MCP-Scan both became standalone CLIs in v4.5.0, so each module runs independently of the main binary.

Maintenance read: cadence, fixes, and data hygiene

  • Two releases in four days (v4.5.0 on 2026-07-27, v4.5.1 on 2026-07-30), each with dozens of changelog entries — fast iteration, but upgrades deserve testing.
  • Community input lands: PRs #458 and #469 (MCP rules), #459 (component fingerprints), and #427 (agentic-tool-misuse dataset) shipped in v4.5.0; the fix for issue #331's frontend checkbox jumping shipped in v4.5.1.
  • Rule data gets corrected, not just appended: v4.5.0 removed 4 CVE rules without matching fingerprints, fixed YAML parse errors in 4 vuln rule files, and cleaned duplicate fingerprints and directories.
  • Docs exist in 9 README languages and counts drift: v4.5.1 corrected CVE counts from 1600+ to 1900+ in README_DE and README_RU.
  • User acknowledgements name Tiane and Binus University, and the project syncs a Securing the AI Agent paper across READMEs — signals of real deployment, not just stars.

Who should pay attention?

Good fit if

  • Security engineers auditing MCP servers before production — hardcoded-secrets and insecure-deserialization rules shipped in v4.5.1.
  • Operators running Open WebUI, Jan, crewai, or lobehub, all covered by the v4.5.0 CVE rule additions.
  • Red teamers who want prebuilt multi-turn jailbreak attacks (Many-Shot, PAIR, GOAT, ActorAttack) instead of hand-maintained scripts.
  • Platform builders adding a skill-audit gate to a marketplace, using aig-skill-scan's SARIF 2.1.0 output in CI.

Skip for now if

  • Anyone needing multi-tenant scanning with login and per-user permissions — SECURITY.md states no such system exists.
  • Shops unwilling to send attack prompts to an external LLM API; PromptSecurity requires an operator-supplied API key.
  • Pure network CVE scanning at scale — projectdiscovery nuclei is purpose-built for that job.
  • Environments that cannot run Docker or local binaries; this repo ships no hosted service.

Risks and cautions

Medium

Apache-2.0 licensing and a fast release cadence are real strengths, but the WebUI is authless by design, jailbreak testing depends on an external LLM API key, and detection quality tracks the freshness of the rule data.

  • No login, sessions, or per-user permissions in the WebUI; anyone reaching `-ws-addr` is treated as the operator, so deployments must stay on loopback or a dedicated scan host.
  • The LLM API key sits in config by operator choice — SECURITY.md explicitly classifies key-in-config reports as out of scope.
  • Detection depends on data/vuln and data/fingerprints freshness; the changelog shows rule corrections (duplicate removals, YAML fixes, 4 orphaned CVE rules dropped) alongside additions.
  • A Go core, Python modules, and a Node frontend build make local builds heavier than single-language scanners.
  • Apache-2.0 license, including the patent grant, permits commercial red-team use without royalties.
  • Disclosure runs through GitHub Security Advisories with a published triage gate: exact file/function/line range, `--version` output, a PoC against latest main, and demonstrated impact; contact is [email protected].
  • SECURITY.md publishes its false-positive list (prompt-injection-only chains, TLS-on-loopback claims, self-scan reports), which shortens reporter-maintainer cycles.
  • Prompt injection against AIG itself is out of scope unless it crosses an OS, network, or filesystem boundary — a defensible line for a red-teaming tool.
  • Recommended deployment is a local machine or dedicated scan host with the WebUI on loopback; CLI mode (`aig -target ...`) exposes no network surface at all.

Alternatives to compare

ApproachWhen to useTrade-off
Microsoft PyRIT
You want a Python SDK to script your own LLM red-team pipelines and scoring logic rather than use a fixed scanner UIFree, open source
NVIDIA garak
You need a probe-style LLM vulnerability scanner and already work in PythonFree, open source
projectdiscovery nuclei
Targets are conventional network services; AIG's go.mod already builds on projectdiscovery networking librariesFree, open source
mcp-scan (Invariant Labs)
You only inspect MCP servers and want a focused, lightweight checkerFree, open source
Commercial AI security platforms
You need managed, multi-tenant scanning with SSO, audit trails, and vendor SLAsSubscription

What this trend reveals

Skill auditing as a marketplace gate

Skill-Scan is the newest module: added in v4.5.0, repackaged as aig-skill-scan on PyPI, simplified to a single default LLM, with Stage 2 code audit writing Markdown plus SARIF 2.1.0 output. A skill marketplace could run it before listing a package.

Install aig-skill-scan from PyPI, audit 5-10 published skills, and diff its SARIF findings against a manual review of the same packages.

MCP admission control from scanning rules

MCP rules grew fast in July 2026 — PRs #458 and #469 in v4.5.0, then hardcoded-secrets and insecure-deserialization rules in v4.5.1 — and a mcp-scan-lite module exists specifically for lighter-weight runs.

Run mcp-scan-lite against every MCP server in a staging registry, tally findings per rule, and compare with a manual config review of the same servers.

Fingerprints for the AI component layer

The v4.5.0 data drop added CVE rules for Jan, Open WebUI, crewai, and lobehub plus new AI component fingerprints (PR #459) — exactly the exposed dashboards generic scanners fingerprint poorly.

Deploy one outdated Open WebUI or Jan instance in a lab and confirm AIG identifies the component and fires the matching data/vuln rules.

Best next action

Prove it in one afternoon against a lab target

A loopback test against a deliberately outdated AI component answers the only question that matters: does the fingerprint-plus-CVE-rule combination catch what your current scanners miss?

  1. Build the Docker image from the repo and start it; confirm the WebUI answers on 127.0.0.1:8088 and the `pgrep ai-infra-guard` healthcheck passes.
  2. Stand up one lab target with a known CVE — an outdated Open WebUI, Jan, crewai, or lobehub build, all covered by the v4.5.0 rules.
  3. Run `aig -target <lab-host>` and record which fingerprint matched and which CVE rules fired.
  4. Install aig-skill-scan from PyPI and audit one internal agent skill; inspect the SARIF 2.1.0 output.
  5. If jailbreak testing fits your scope, configure an LLM API key, run one Many-Shot or PAIR attack against a disposable model, then remove the key.

RepoDaily verdict

AI-Infra-Guard is trending because it collapses five tools into one Apache-2.0 binary: agent behavior scans, MCP server checks, skill auditing, 1,700+-rule AI infra CVE scanning, and four families of multi-turn jailbreak attacks. The v4.5.x releases show serious iteration speed — a PyPI package, SARIF output, dual-mode MCP scanning, and named OWASP agent skills inside four days. Run it as a single-operator lab instrument on loopback, keep the rule data current, and skip it if you need a multi-tenant platform; the project itself says it is not one.

Sources