AI-Infra-Guard
A free, open-source security scanner from Tencent that checks your AI infrastructure — agents, MCP servers, and frameworks — for known vulnerabilities and jailbreak weaknesses before an attacker does.
🔗 Visit AI-Infra-GuardDescription
Deploying an AI agent framework or an MCP server usually means trusting a fast-moving open-source stack you haven't had time to audit yourself — and unlike a web server, there's no mature, well-known checklist yet for what "secure" looks like. AI-Infra-Guard, built by Tencent's Zhuque Lab, is a self-assessment tool for exactly that gap: point it at your AI stack and it scans for known vulnerabilities and misconfigurations before someone else finds them for you.
It works across several layers at once: infrastructure vulnerability scanning checks over 100 AI framework components against more than 2,000 known CVEs, Agent Scan and MCP/Skill Scanning look for risky configurations across 14+ security categories in agent workflows, and a jailbreak evaluation module runs multi-attack tests against your models to check robustness. It ships as a Docker deployment with a web UI and Swagger-documented REST API, plus standalone CLI tools for each scan type. The core tool is free and open source under Apache 2.0; a Pro version exists but currently requires an invitation code to access.
💬 Our review
The short version: if you're running AI agents, MCP servers, or LLM-based infrastructure in production and haven't had a security review, AI-Infra-Guard is a free way to catch the obvious gaps — coming from Tencent's security research lab gives it more credibility than a random side project in a space with few established tools yet.
There isn't a direct, equally comprehensive open-source competitor covering infrastructure CVEs, agent/MCP scanning, and jailbreak testing all in one tool — most existing security scanners focus on traditional web/cloud infrastructure and don't yet understand AI-specific attack surfaces like MCP servers or agent tool-calling. The tradeoff is that it's resource-heavy (4GB+ RAM, 10GB+ disk) and clearly built for security teams comfortable with Docker deployments and CLI tools, not a point-and-click consumer product. For any team running AI infrastructure in production without a dedicated AI security specialist, running this once is a low-cost way to find out what you don't know; for a hobbyist project, it's likely overkill.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Gratuit, licence Apache 2.0. Version Pro existante mais accès actuellement sur invitation uniquement.
Pros
Couvre infrastructure, agents, MCP et robustesse LLM en un seul outil
Détecte 2000+ vulnérabilités connues sur 100+ composants de frameworks IA
Gratuit et open source (Apache 2.0)
Développé par le laboratoire sécurité Zhuque de Tencent
Déploiement Docker avec interface web et API REST documentée
Cons
Version Pro sur invitation uniquement
Ressources conséquentes requises (4 Go+ RAM, 10 Go+ disque)
Complexité de mise en place pour des équipes non techniques
Documentation limitée pour les développeurs individuels
