Tencent/AI-Infra-Guard: a self-hosted AI red teaming platform for MCP, agents and model APIs
A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
At a glance
- What is it?
- A.I.G bundles OpenClaw and Skills scanning, MCP server checks, AI infrastructure vulnerability scanning and jailbreak evaluation into one Docker-deployed service. It is aimed at teams that already run agents and MCP tooling and want a repeatable way to probe them before someone else does.
- Who is it for?
- Adopt AI-Infra-Guard if you already run MCP servers, agent skills or self-hosted model endpoints and want a single self-hosted service that scans them, because the CLI tools for skill-scan, mcp-scan and agent-scan ship in the repository and the Docker Compose file wires the web UI to the checker agent on port 8000.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 6 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What AI-Infra-Guard actually checks
AI-Infra-Guard, abbreviated A.I.G, is a full-stack AI red teaming platform from Tencent Zhuque Lab. The README lists its capabilities as OpenClaw Security Scan (ClawScan), Agent Scan, AI infrastructure vulnerability scanning, MCP Server and Agent Skills scanning, and jailbreak evaluation. Those are five different targets, not one, and that is the point: a team running an agent stack usually has a model endpoint, an MCP server, a set of installed skills and the underlying inference infrastructure, and each of those has a different failure mode.
The audience is narrower than the name suggests. This is not a tool for someone who has never deployed a model. It assumes you have MCP servers registered, skills installed from a marketplace, or a self-hosted inference stack such as llama.cpp that you want checked against known CVEs. The repository includes a skill-scan directory, an mcp-scan directory and an agent-scan directory, each exposed as a standalone CLI, plus a web frontend for the combined platform. If your AI usage is a single hosted API call from a script, most of the platform is irrelevant to you.
How the web service, the checker agent and the CLIs fit together
The docker-compose.yml file shows a two-container design. The webserver container builds from Dockerfile, publishes port 8088, and talks to a second container named agent over the internal network. The webserver passes AIG_API_CHECKER_URL=http://agent:8000 into its own environment, and the agent container exposes port 8000 only on the compose network, not to the host.
The agent container is where the heavier scanning work happens. It runs with cap_add SYS_ADMIN, security_opt seccomp:unconfined and shm_size 2gb, which the compose file sets because the API checker needs more privileges and shared memory than a default container gets. Its healthcheck calls /healthz on 127.0.0.1:8000 using the Python interpreter inside /app/api-checker-venv. The webserver waits on that healthcheck through depends_on with condition: service_healthy, so the UI does not come up before the checker is answering.
Configuration for the checker is environment-driven. AIG_API_CHECKER_MAX_JOBS defaults to 20 concurrent jobs. AIG_API_CHECKER_ALLOW_HTTP defaults to 0, and AIG_API_CHECKER_ALLOW_PRIVATE_TARGETS also defaults to 0, which means the checker will not scan plain HTTP targets or private addresses unless you explicitly turn those on. That default matters: if you want to point the scanner at an internal MCP server on a private address, the scan will be refused until you change that variable. The Go module list shows the project leans on ProjectDiscovery libraries such as fastdialer, rawhttp and retryablehttp-go for the network side, and on mcp-go for MCP interaction, which is consistent with a scanner that speaks raw HTTP and MCP rather than only driving a browser.
Installing AI-Infra-Guard with Docker Compose
The README states the Docker path needs Docker 20.10 or higher, 4GB of RAM and 10GB of disk. The documented quick start clones the repository and brings up the pre-built image compose file, which pulls from Docker Hub rather than building locally.
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
docker-compose -f docker-compose.images.yml up -dThe README notes that on Docker Compose V2 and later you should replace docker-compose with docker compose. After the containers start, the web interface is documented at http://localhost:8088. There is a second compose file, docker-compose.yml, which builds both images from source instead of pulling them, and a one-click script that installs Docker and launches A.I.G in a single command.
curl https://raw.githubusercontent.com/Tencent/AI-Infra-Guard/refs/heads/main/docker.sh | bashThe README labels that script as the recommended method and states it installs Docker automatically. Treat it accordingly: piping a remote script into bash is a decision about trust, and the file lives at the repository root if you would rather read it first.
For a first real use, the repository exposes skill-scan, mcp-scan and agent-scan as standalone CLIs, which is often a faster way to see output than going through the UI. The README also documents calling A.I.G from an OpenClaw chat through the aig-scanner skill.
clawhub install aig-scannerAfter installing that skill you set AIG_BASE_URL to point at your running A.I.G service, and the aig-scanner README in the skills directory covers the rest. If you prefer the browser, start a scan from the web UI at port 8088 and confirm through the agent container logs that jobs are being picked up, since the checker is a separate process.
What the release notes say about detection coverage
The What's New section is the most concrete source of scope information, and it is worth reading as a changelog of detection categories rather than as a feature list. Version 4.6.0 on 2026-08-26 added LLM API poisoning detection, described as a multi-probe black-box audit for model substitution and backdoor risks, along with an Agent-Scan v5.0.0 mutation engine refactor. The same entry states the vulnerability library expanded to 146 AI components and over 2000 CVE rules.
Version 4.5.2 on 2026-08-17 added .pyc bytecode bypass detection and charset smuggling defense to Skill-Scan, and RCE prevention via tool whitelisting in MCP-Scan dynamic mode. Version 4.5.1 on 2026-07-30 added four multi-turn jailbreak attacks named Many-Shot, PAIR, GOAT and ActorAttack, plus five new OWASP skills and web-exfiltration detection in Agent-Scan. Version 4.5.0 on 2026-07-27 launched an AI Security Skill Market with three official skills and reported a SkillTrustBench score of 0.9848 for the skill scan engine.
Two things follow from that sequence. First, the project is moving fast enough that the scan rules you get depend heavily on which version you deploy, so pinning an image tag is worth considering. Second, several entries are framed as defenses against bypasses of the scanner itself, such as .pyc bytecode bypass and charset smuggling. That tells you the scan targets are adversarial by nature and that a clean result from an older version should not be treated as final.
Where AI-Infra-Guard is the wrong tool
The checker defaults are the first real limitation. With AIG_API_CHECKER_ALLOW_PRIVATE_TARGETS set to 0, the agent will not scan private targets, and with AIG_API_CHECKER_ALLOW_HTTP at 0 it will not scan plain HTTP endpoints. Most internal MCP servers and staging model endpoints sit on private addresses and speak HTTP behind a proxy, so a first run against your own lab will likely be blocked until you flip those variables. That is a sensible safe default, but it means the out-of-the-box experience is aimed at externally reachable or TLS-fronted targets, which is not where most teams start.
The privilege profile is the second constraint. The agent container requests SYS_ADMIN and unconfined seccomp, and asks for 2GB of shared memory. Running that on a shared Kubernetes cluster or a hardened host will require policy exceptions, and some platform teams will simply refuse. The compose file also mounts ./data, ./db, ./logs and ./uploads from the host, so the deployment writes state next to the checkout.
The third limitation is scope. This is an AI-specific scanner, not a general vulnerability management platform. It will not replace your existing network scanning, dependency auditing or cloud posture tooling. If your AI footprint is a thin wrapper over a hosted model API with no MCP servers, no installed skills and no self-hosted inference, the platform has little to scan and you would be better served by reviewing your prompt-handling code directly. The README also does not document a rollback or downgrade procedure, so plan upgrades around the release notes rather than expecting a documented revert path.
How it differs from generic LLM red teaming frameworks
The obvious comparison is with prompt-focused red teaming frameworks such as Garak or PyRIT, which concentrate on probing a model's text behaviour: generating adversarial prompts, measuring refusal rates and scoring outputs. AI-Infra-Guard does include jailbreak evaluation, but the jailbreak module is one component among several rather than the centre of the product.
The difference in approach is the target. A prompt-level framework treats the model as the attack surface. AI-Infra-Guard treats the surrounding system as the attack surface: the MCP server that exposes tools, the skill package that runs code, the agent that chains them, and the inference infrastructure underneath. The release notes reflect that emphasis, with entries about tool whitelisting in MCP dynamic mode and bytecode bypass detection in skill packages rather than about prompt phrasing alone. If your concern is that an installed skill exfiltrates data through a web request, a prompt-level framework will not see it. If your concern is that your model can be talked into producing harmful text, AI-Infra-Guard's jailbreak module covers part of that ground but the dedicated frameworks go deeper. The two categories are complementary, and the honest framing is that neither replaces the other.
Licence, attribution and the cost of keeping up
The repository is licensed under Apache-2.0 and ships a separate NOTICE file at the root. Apache-2.0 permits commercial use and modification, and it requires that you retain copyright and attribution notices and include a copy of the licence. The presence of NOTICE means there is additional attribution material to carry forward if you redistribute the software or a modified version. This is a description of what the files say, not legal advice; if you plan to redistribute A.I.G inside a product, have counsel read the LICENSE and NOTICE together.
Upgrade cost is the more practical expense. The release cadence in the What's New section is roughly one release every two to four weeks across July and August 2026, and the last push to the repository was on 2026-08-26. Each release changes scan rules, and version 4.5.0 moved the frontend to fully open source while 4.6.0 refactored the Agent-Scan mutation engine. Rule libraries that expand this quickly also mean results are not stable across versions, so a finding that disappears after an upgrade may reflect a rule change rather than a fix. Budget for pinning image tags, reading the CHANGELOG before each bump, and re-running a fixed baseline scan after upgrading so you can tell which differences are yours and which are the scanner's.
Editorial conclusion
Adopt AI-Infra-Guard if you already run MCP servers, agent skills or self-hosted model endpoints and want a single self-hosted service that scans them, because the CLI tools for skill-scan, mcp-scan and agent-scan ship in the repository and the Docker Compose file wires the web UI to the checker agent on port 8000. Do not adopt it as a general network vulnerability scanner or as a hosted SaaS, since the deployment is Docker-based and the API checker keeps private-target access off by default. Before rolling it out, verify that your host meets the 4GB RAM and 10GB disk requirement, decide whether AIG_API_CHECKER_ALLOW_PRIVATE_TARGETS needs to be enabled for internal endpoints, and read the NOTICE file alongside the Apache-2.0 LICENSE to confirm how attribution applies to your distribution.
Frequently asked questions
What are AI guardrails used for?
The README frames AI-Infra-Guard as a self-examination tool for AI security risk, covering OpenClaw Security Scan, Agent Scan, AI infrastructure vulnerability scanning, MCP Server and Agent Skills scanning, and jailbreak evaluation. Each capability targets a different part of an agent stack rather than the model's text output alone.
How do I install AI-Infra-Guard?
The README documents a Docker Compose deployment that clones the repository and runs docker-compose -f docker-compose.images.yml up -d, requiring Docker 20.10 or higher, 4GB of RAM and 10GB of disk. The web interface is then available at http://localhost:8088. A one-click script and a build-from-source compose file are also documented.
Does AI-Infra-Guard scan private or internal targets?
Not by default. The agent container sets AIG_API_CHECKER_ALLOW_PRIVATE_TARGETS and AIG_API_CHECKER_ALLOW_HTTP to 0, so private addresses and plain HTTP targets are refused until those environment variables are changed in docker-compose.yml.
What components does the AI-Infra-Guard vulnerability library cover?
The v4.6.0 release notes state the vulnerability library was expanded to 146 AI components and more than 2000 CVE rules. Earlier entries describe growth from 130 components and 1888 rules in v4.5.0.
Can AI-Infra-Guard be called from OpenClaw chat?
Yes. The README documents installing the aig-scanner skill with clawhub install aig-scanner and then setting AIG_BASE_URL to point at a running A.I.G service. Details are in the aig-scanner README under the skills directory.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/tencent-ai-infra-guard)