Tencent AI-Infra-Guard: Full-Stack AI Red Teaming for Agents, MCP, and Infra
Tencent Zhuque Lab open-sourced AI-Infra-Guard (A.I.G), an AI red teaming platform scanning agent jailbreaks, MCP server risks, and 400+ AI framework CVEs.
Tencent Zhuque Lab, the cybersecurity research team at Tencent, has open-sourced AI-Infra-Guard (A.I.G) under the Apache 2.0 license. The platform provides an all-in-one AI red teaming suite designed to systematically evaluate security vulnerabilities across LLM applications, autonomous AI agents, Model Context Protocol (MCP) servers, and local inference infrastructure.
As enterprises and developers rapidly deploy autonomous agent frameworks, MCP tool integrations, local inference backends such as Ollama and vLLM, and workflow automation platforms like LangFlow and n8n, AI systems are exposing critical attack vectors that conventional web application scanners cannot detect. AI-Infra-Guard bridges this gap by unifying prompt jailbreak evaluation, agent hijacking detection, tool schema manipulation testing, malicious skill injection auditing, and automated CVE scanning for AI infrastructure components into a single self-hosted testing platform.
Core Diagnostic Capabilities: From Agent Jailbreaks to Infrastructure CVEs
AI-Infra-Guard features a modular scanning architecture tailored to different layers of the modern AI technology stack.
- Agent Security Scanning (Agent Scan): Evaluates AI agents built on frameworks like Dify, Coze, or custom HTTP endpoints against indirect prompt injection, privilege escalation, unauthorized tool execution, and role breaking. It integrates specialized agent control-loss benchmarks (such as FORGE-Bench and RogueHandoff-20) to assess risks in multi-step autonomous workflows.
- MCP Server and Agent Skills Scan: Analyzes tool definitions and schema tampering vulnerabilities across MCP servers connected to AI agents. Powered by the ClawScan engine, it performs security checks for OpenClaw and detects malicious agent skill injection, while supporting Server-Sent Events (SSE) connections and configurable reasoning effort forwarding for supported LLM APIs.
- AI Infrastructure Vulnerability Scanner (AI Infra Scan): Automatically discovers over 30 leading AI framework components—including Ollama, vLLM, ComfyUI, LangFlow, n8n, PraisonAI, llama-cpp, and MLflow—and executes batch scans across more than 400 cataloged CVEs, such as the React2Shell vulnerability (CVE-2025-55182).
- LLM Jailbreak Evaluation: Generates multi-turn adversarial prompt variations to benchmark the resilience of target model guardrails, complemented by an API Checker module that verifies model fingerprints and safety filter configurations.
- Composable Prompt Injection Research Toolkit (pikit): Embeds the modular pikit toolkit under
Research/pikitto support custom red-teaming research, attack payload authoring, and penetration testing experiments.
REST API Interface and One-Click Docker Deployment
AI-Infra-Guard is engineered for straightforward integration into automated DevSecOps pipelines and continuous testing workflows.
- Standard REST API (
api.md): Exposes dedicated endpoints for Agent Scan, MCP Server Scan, Jailbreak Evaluation, and AI Infra Scan, enabling CI/CD systems and security orchestration tools to trigger scans programmatically and retrieve structured JSON reports. - One-Click Docker Deployment: Provides an automated Linux Docker setup script alongside official Docker Compose manifests, allowing teams to quickly spin up an isolated, self-hosted testing instance without dependency conflicts.
- Operational Controls and Multilingual Docs: Includes built-in concurrency limiters for LLM API calls, responsive security report views tailored for both desktop and narrow screens, and multilingual documentation covering English, Korean, Chinese, Japanese, and several other languages.
Target Audience and Operational Considerations
AI-Infra-Guard serves development teams deploying AI agents and MCP tools into production, platform engineers managing internal AI clusters, and security red teams conducting specialized AI penetration tests.
When deploying the platform in practical environments, teams should keep the following factors in mind:
- Self-Hosting and BYOK Configuration: Teams must prepare an isolated Docker environment and configure target LLM API endpoints and credentials (Bring Your Own Key) to evaluate diagnostic payloads.
- API Call Volume and Rate Limiting: Full-scale agent scans and jailbreak evaluations generate substantial volumes of LLM API requests, making it essential to monitor endpoint rate limits and token budgets in advance.
- Authorized Testing Scope: As a dedicated red teaming and security scanning platform, assessments should be strictly directed at authorized internal infrastructure, staging deployments, and sandboxed testing targets.
Sources
- GitHub Repository: Tencent/AI-Infra-Guard
- Official API Documentation: Tencent/AI-Infra-Guard api.md
- Security & Tech (@ngnicky) X Post: 2026-10-03 AI-Infra-Guard Discovery Signal