AI-Infra-Guard

AI-Infra-Guard

A free, open-source security scanner from Tencent that checks your AI infrastructure — agents, MCP servers, and frameworks — for known vulnerabilities and jailbreak weaknesses before an attacker does.

🔗 Visit AI-Infra-Guard
📁 Security & Privacy🗣️ English📅 August 25, 2026

Description

Deploying an AI agent framework or an MCP server usually means trusting a fast-moving open-source stack you haven't had time to audit yourself — and unlike a web server, there's no mature, well-known checklist yet for what "secure" looks like. AI-Infra-Guard, built by Tencent's Zhuque Lab, is a self-assessment tool for exactly that gap: point it at your AI stack and it scans for known vulnerabilities and misconfigurations before someone else finds them for you.

It works across several layers at once: infrastructure vulnerability scanning checks over 100 AI framework components against more than 2,000 known CVEs, Agent Scan and MCP/Skill Scanning look for risky configurations across 14+ security categories in agent workflows, and a jailbreak evaluation module runs multi-attack tests against your models to check robustness. It ships as a Docker deployment with a web UI and Swagger-documented REST API, plus standalone CLI tools for each scan type. The core tool is free and open source under Apache 2.0; a Pro version exists but currently requires an invitation code to access.

💬 Our review

The short version: if you're running AI agents, MCP servers, or LLM-based infrastructure in production and haven't had a security review, AI-Infra-Guard is a free way to catch the obvious gaps — coming from Tencent's security research lab gives it more credibility than a random side project in a space with few established tools yet.

There isn't a direct, equally comprehensive open-source competitor covering infrastructure CVEs, agent/MCP scanning, and jailbreak testing all in one tool — most existing security scanners focus on traditional web/cloud infrastructure and don't yet understand AI-specific attack surfaces like MCP servers or agent tool-calling. The tradeoff is that it's resource-heavy (4GB+ RAM, 10GB+ disk) and clearly built for security teams comfortable with Docker deployments and CLI tools, not a point-and-click consumer product. For any team running AI infrastructure in production without a dedicated AI security specialist, running this once is a low-cost way to find out what you don't know; for a hobbyist project, it's likely overkill.

💰 Pricing

GratuitOpen source, Apache 2.0. Version Pro sur invitation.

📊 Global score

53Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile90/100Excellent

Profile completeness

🤖 AI-enriched data

💰 Pricing model
🆓 Gratuit (open source)

Gratuit, licence Apache 2.0. Version Pro existante mais accès actuellement sur invitation uniquement.

👥 Target audienceÉquipes sécurité et entreprises déployant des agents IA, serveurs MCP ou frameworks IA en production
🗣️ Languagesen
🌍 Target countriesInternational
👍

Pros

Couvre infrastructure, agents, MCP et robustesse LLM en un seul outil

Détecte 2000+ vulnérabilités connues sur 100+ composants de frameworks IA

Gratuit et open source (Apache 2.0)

Développé par le laboratoire sécurité Zhuque de Tencent

Déploiement Docker avec interface web et API REST documentée

👎

Cons

Version Pro sur invitation uniquement

Ressources conséquentes requises (4 Go+ RAM, 10 Go+ disque)

Complexité de mise en place pour des équipes non techniques

Documentation limitée pour les développeurs individuels

❓ Frequently asked questions

What is AI-Infra-Guard in one sentence?
How much does it cost?
What does it actually scan?
How is it deployed?
Who built it?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?