A.I.G (AI Infra Guard) vs Port Radar for macOS: Features, Pricing & Which Is Better (2026)
A side-by-side comparison of A.I.G (AI Infra Guard) and Port Radar for macOS — features, pricing, and ideal use cases — to help you decide which AI tool fits your workflow.
A.I.G (AI Infra Guard)
Tencent Zhuque Lab
Tencent's open-source AI red teaming platform for scanning agents, agent skills, MCP servers and AI infrastructure, plus LLM jailbreak evaluation.
Key features
- Agent Skills Scan: Audits agent skill packages against a nine-category risk taxonomy aligned with the public SkillTrustBench T01-T09 classification, including detection of .pyc bytecode bypasses and charset smuggling.
- MCP Server Scan: Inspects MCP servers for threats such as tool poisoning, credential exfiltration and command injection, with tool whitelisting to prevent remote code execution during dynamic scanning.
- AI Infrastructure Vulnerability Scanning: Checks deployed AI components against a library that has grown to roughly 130 components and over 2,000 CVE rules, covering frameworks such as llama.cpp.
- Jailbreak Evaluation: Runs single-turn jailbreak operators plus multi-turn attack techniques including Many-Shot, PAIR, GOAT and ActorAttack to measure a model's resistance.
- Agent Scan with OWASP Coverage: Assesses running agents using OWASP-derived skills and web exfiltration detection, with a dedicated agent red team skill for comprehensive assessment.
- Standalone Scanner CLIs: skill-scan, mcp-scan and agent-scan each install as an independent command-line tool so scans can be wired directly into enterprise CI/CD pipelines.
- Docker Deployment with Web UI: Deploy the full platform with Docker on 4GB+ RAM and reach the web interface at localhost:8088, or use a one-click install script or a source build.
- AI Security Skill Market: A catalog of official security scanning skills, with the frontend fully open-sourced and integration available from OpenClaw chat via the aig-scanner skill.
Best for
- Pre-Deployment Agent Audit: Scan an internally built agent and its skill bundle for prompt injection, exfiltration and privilege risks before it is released to staff.
- MCP Supply Chain Review: Vet third-party MCP servers for tool poisoning and credential exfiltration before connecting them to production assistants.
- CI/CD Security Gate: Run skill-scan as a standalone CLI on every pull request so risky agent skills fail the build rather than shipping.
- Model Safety Benchmarking: Measure how a deployed LLM holds up against single and multi-turn jailbreak techniques before and after guardrail changes.
- AI Infrastructure Patch Triage: Inventory AI serving components and match them against the CVE rule library to prioritise which hosts need patching.
- Security Research and Reporting: Use the open scan engines and SkillTrustBench alignment as a reproducible basis for internal or published AI security research.
Port Radar for macOS
Juan Sebastian Solano
Free open-source Mac menu bar app that lists every listening localhost port and uses on-device Apple Intelligence to explain what each process is.
Key features
- Menu Bar Port Scanner: Lists every listening localhost port in the menu bar with port number, PID, owning project, runtime, and the exact command line.
- Apple Intelligence Explanations: Ask in plain language what a process is, why it has been running, and whether stopping it is safe; answers are generated on-device with no cloud call.
- Project Grouping: Groups processes by the project directory that owns them and flags shared or orphaned processes with no obvious parent.
- One-Click Cloudflare Tunnels: Share any local port as a public URL through a Cloudflare quick tunnel, auto-installing cloudflared with no CLI, ngrok, or account setup.
- Clean Process Control: Stop a process gracefully or force-quit it with a confirmation step, directly from the menu bar.
- Live Tunnel Management: See which tunnels are currently live and public, copy their URLs, and stop them at any time.
- Fully On-Device Privacy: All inspection and AI explanation happens locally; no process data or command lines are sent off the machine.
- Open Source Under Apache 2.0: The full source is published on GitHub, so the app can be audited or built from source.
Best for
- Port Conflict Debugging: Finding out which forgotten process is holding port 3000 before starting a new dev server.
- Runaway Process Triage: Identifying a Node or Python process quietly eating CPU and deciding whether it is safe to kill.
- Preview Sharing: Handing a teammate or client a live public URL for a work-in-progress local app in seconds.
- Multi-Project Development: Keeping track of which of several simultaneously running projects owns each active port.
- Onboarding and Handover: Letting a developer new to a codebase understand what the local stack actually starts up.
- Privacy-Sensitive Environments: Getting AI assistance about local processes in settings where sending command lines to a cloud model is unacceptable.
