█

AI/TLDR

AI-Infra-Guard

Scan agents, skills, MCP servers and AI infra for vulnerabilities, then jailbreak-test the model

Security AgentsOpen source
Latest
v4.6.1
Updated
10 Sep 2026
Language
Python
License
Apache-2.0
$git clone https://github.com/Tencent/AI-Infra-Guard.git

What's new

v4.6.110 Sep 2026

API Checker expands model fingerprint coverage to Gemini 2.5/3.1, Gemma 2/3/4 and GLM-5.3, and MCP-Scan now flags empty or incomplete scans, preserves security findings through context compaction and surfaces underlying connection errors.

Overview

AI-Infra-Guard — A.I.G — is an open-source AI red teaming platform from Tencent's Zhuque Lab. It bundles several scanners into one self-hostable service: agent scanning, Agent Skills and MCP server security audits, AI infrastructure vulnerability scanning against a CVE library, an LLM API and relay checker, and jailbreak evaluation of the model itself.

The Skills scanner is the part with published numbers. It classifies findings against the SkillTrustBench T01–T09 taxonomy — skill instruction hijacking and memory poisoning; remote payload download and embedded malicious code; privilege escalation and system persistence; tool hijacking and insecure dependencies; and insecure coding practices — covering the routes by which an installed skill can act against the user who installed it. It ships separately as the pip-installable aig-skill-scan CLI, which is designed to drop into a CI/CD pipeline.

The MCP and agent scanners cover the adjacent surface: an MCP server is remote code someone else wrote that your agent is about to trust, and A.I.G checks it before that happens. Alongside them the vulnerability library tracks CVE rules across AI components, and the API checker fingerprints models behind an API relay to detect model substitution and backdoor risks. A.I.G is positioned for internal use by an enterprise or individual: it has no authentication mechanism of its own and the project explicitly warns against deploying it on a public network.

What it does

  • Agent Skills security audit classified against the SkillTrustBench T01–T09 risk taxonomy, shipped as the standalone aig-skill-scan CLI for CI/CD
  • MCP server scanning, with tool whitelisting in dynamic mode to prevent RCE during the scan itself
  • Agent scanning and AI infrastructure vulnerability scanning against a CVE rule library
  • LLM jailbreak evaluation including multi-turn attacks (Many-Shot, PAIR, GOAT, ActorAttack)
  • Model and API relay checker that fingerprints the model actually serving a relay endpoint, auditing for substitution and backdoor risk
  • Self-hosted web interface via Docker Compose, plus standalone skill-scan, mcp-scan and agent-scan CLIs

Getting started

The full platform runs as a Docker Compose stack with a web UI. If you only want the skills audit in a pipeline, install the aig-skill-scan CLI on its own. Docker 20.10+, 4GB RAM and 10GB disk are the stated requirements.

Run the platform with Docker

This pulls pre-built images from Docker Hub for a faster start. For Docker Compose V2+, use 'docker compose' in place of 'docker-compose'.

bashbash
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker-compose -f docker-compose.images.yml up -d

Open the web interface

A.I.G has no built-in authentication and is meant for internal use only — do not expose this port to a public network.

bashbash
# http://localhost:8088

Scan a skill from CI

The skills auditor installs on its own from PyPI and writes JSON, so it can gate a pipeline. It calls an LLM, so it needs an API key and a model.

bashbash
pip install aig-skill-scan

# Set API key via environment variable
export LLM_API_KEY="your-api-key"

# Scan a local Skill project directory
aig-skill-scan --repo /path/to/your/skill \
           -m deepseek-v4-flash \
           --language en \
           -o result.json

Build from source instead

Builds the Docker image from local source rather than pulling published images. A one-click script that also installs Docker is documented in the README.

bashbash
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker-compose up -d

Commands and code are distilled from the project's own documentation — always check the official repo for the latest.

When to use it

  • Audit an Agent Skill before installing it, checking for instruction hijacking, embedded malicious code or privilege escalation
  • Gate a CI/CD pipeline on aig-skill-scan so a skill with T01–T09 findings never reaches a shared marketplace or internal registry
  • Vet a third-party MCP server your agents are about to be given access to
  • Jailbreak-test a deployed model with multi-turn attacks, or verify that an API relay is serving the model it claims to serve

Version history

Every verified update to AI-Infra-Guard that AI/TLDR tracked, newest first — each links to our coverage and the official changeset.

  1. 2026-09-10v4.6.1

    API Checker expands model fingerprint coverage to Gemini 2.5/3.1, Gemma 2/3/4 and GLM-5.3, and MCP-Scan now flags empty or incomplete scans, preserves security findings through context compaction and surfaces underlying connection errors.

  2. 2026-08-26v4.6.0

    Adds LLM API poisoning detection, a multi-probe black-box audit for model substitution and backdoor risks, and refactors the Agent-Scan mutation engine. The vulnerability library grows to 146 AI components and over 2000 CVE rules.

  3. 2026-07-27v4.5.0

    Open-sources the frontend, launches the AI Security Skill Market, and upgrades the skill scan engine to nine risk categories. Skill, MCP and agent scans become standalone CLIs.

How AI-Infra-Guard compares

AI-Infra-Guard alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.

ToolStarsWhat it does
PentAGI★ 25.2kPentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools.
PentestGPT★ 15.7kAn open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop.
IDA Pro MCP★ 12.4kAn MCP server and IDA Pro plugin that exposes decompilation, cross-references, renaming and type editing to an LLM client, letting an agent read and annotate a binary inside your IDA database.
HexStrike AI★ 12.3kAn MCP server that gives an AI agent a single interface to 150+ installed security tools — Nmap, Nuclei, SQLMap, Ghidra, Hashcat and more — so it can drive reconnaissance, scanning and binary analysis itself.
CAI★ 9.8kCAI (Cybersecurity AI) is an open-source Python framework for building AI agents that automate offensive and defensive security tasks like recon, vulnerability discovery, and exploitation.
AI-Infra-Guard★ 6.7kScan agents, skills, MCP servers and AI infra for vulnerabilities, then jailbreak-test the model
T3MP3ST★ 6.3kA multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI.
RedAmon★ 2.9kA Docker-deployed offensive-security platform for authorised testing that chains parallel recon, exploitation and post-exploitation into a Neo4j attack graph, then triages the findings and opens remediation pull requests on your repository.