linkgo

Agent Skills vs A.I.G (AI Infra Guard): Features, Pricing & Which Is Better (2026)

A side-by-side comparison of Agent Skills and A.I.G (AI Infra Guard) — features, pricing, and ideal use cases — to help you decide which AI tool fits your workflow.

A

Agent Skills

Addy Osmani

Free

Open-source library of production-grade engineering skills that make AI coding agents follow senior-engineer workflows across the full dev lifecycle.

Key features

  • Lifecycle Slash Commands: Seven commands (/spec, /plan, /build, /test, /review, /code-simplify, /ship) that map to each phase of development.
  • Auto Build Mode: /build auto generates a plan and implements every task autonomously after a single approval.
  • Test-Driven Execution: Each task is test-driven and committed individually, pausing on failures or risky steps.
  • Automatic Skill Activation: Skills activate based on what the developer is currently doing, without manual selection.
  • Quality Gates: Encodes review and QA gates so agents enforce code-health standards before shipping.
  • Spec-First Workflow: Enforces writing a spec and plan before code to keep agent output structured.

Best for

  • Structured Agent Coding: Guide an AI coding agent through spec, plan, build, test, and ship in a disciplined flow.
  • Autonomous Feature Builds: Approve a plan once and let the agent implement all tasks with per-task tests.
  • Code Review Automation: Apply consistent review and simplification gates before merging.
  • Onboarding Best Practices: Encode senior-engineer workflows so every project follows the same quality standards.
  • Reducing Manual Steps: Cut the human hand-offs between tasks while preserving verification.
View Agent Skills details
A.I.G (AI Infra Guard) logo

A.I.G (AI Infra Guard)

Tencent Zhuque Lab

Free

Tencent's open-source AI red teaming platform for scanning agents, agent skills, MCP servers and AI infrastructure, plus LLM jailbreak evaluation.

Key features

  • Agent Skills Scan: Audits agent skill packages against a nine-category risk taxonomy aligned with the public SkillTrustBench T01-T09 classification, including detection of .pyc bytecode bypasses and charset smuggling.
  • MCP Server Scan: Inspects MCP servers for threats such as tool poisoning, credential exfiltration and command injection, with tool whitelisting to prevent remote code execution during dynamic scanning.
  • AI Infrastructure Vulnerability Scanning: Checks deployed AI components against a library that has grown to roughly 130 components and over 2,000 CVE rules, covering frameworks such as llama.cpp.
  • Jailbreak Evaluation: Runs single-turn jailbreak operators plus multi-turn attack techniques including Many-Shot, PAIR, GOAT and ActorAttack to measure a model's resistance.
  • Agent Scan with OWASP Coverage: Assesses running agents using OWASP-derived skills and web exfiltration detection, with a dedicated agent red team skill for comprehensive assessment.
  • Standalone Scanner CLIs: skill-scan, mcp-scan and agent-scan each install as an independent command-line tool so scans can be wired directly into enterprise CI/CD pipelines.
  • Docker Deployment with Web UI: Deploy the full platform with Docker on 4GB+ RAM and reach the web interface at localhost:8088, or use a one-click install script or a source build.
  • AI Security Skill Market: A catalog of official security scanning skills, with the frontend fully open-sourced and integration available from OpenClaw chat via the aig-scanner skill.

Best for

  • Pre-Deployment Agent Audit: Scan an internally built agent and its skill bundle for prompt injection, exfiltration and privilege risks before it is released to staff.
  • MCP Supply Chain Review: Vet third-party MCP servers for tool poisoning and credential exfiltration before connecting them to production assistants.
  • CI/CD Security Gate: Run skill-scan as a standalone CLI on every pull request so risky agent skills fail the build rather than shipping.
  • Model Safety Benchmarking: Measure how a deployed LLM holds up against single and multi-turn jailbreak techniques before and after guardrail changes.
  • AI Infrastructure Patch Triage: Inventory AI serving components and match them against the CVE rule library to prioritise which hosts need patching.
  • Security Research and Reporting: Use the open scan engines and SkillTrustBench alignment as a reproducible basis for internal or published AI security research.
View A.I.G (AI Infra Guard) details