

Tencent's open-source AI red teaming platform for scanning agents, agent skills, MCP servers and AI infrastructure, plus LLM jailbreak evaluation.

Tencent's open-source AI red teaming platform for scanning agents, agent skills, MCP servers and AI infrastructure, plus LLM jailbreak evaluation.
A.I.G (AI Infra Guard) is an open-source AI red teaming platform from Tencent's Zhuque Lab that consolidates several AI security self-assessment capabilities into one deployable service. It combines Agent Scan, Agent Skills Scan, MCP Server Scan, AI infrastructure vulnerability scanning and LLM jailbreak evaluation, so a team can audit an entire AI stack rather than one component at a time. The vulnerability library has grown to cover roughly 130 components and 2,000+ CVE rules, while the skill scan engine classifies findings across nine risk categories aligned with Tencent's public SkillTrustBench T01–T09 taxonomy. Each scanner also ships as a standalone CLI so it can drop into enterprise CI/CD pipelines, and the whole platform deploys via Docker with a web interface on port 8088. Recent releases added multi-turn jailbreak attacks such as Many-Shot, PAIR, GOAT and ActorAttack, Python bytecode bypass detection for skills, and an AI Security Skill Market. The project has been presented at Black Hat EU Arsenal and notes it has no built-in authentication, so it is intended for internal rather than public-network deployment.
Tencent's open-source AI red teaming platform for scanning agents, agent skills, MCP servers and AI infrastructure, plus LLM jailbreak evaluation.
A.I.G (AI Infra Guard) works by combining Agent Skills Scan: Audits agent skill packages against a nine-category risk taxonomy aligned with the public SkillTrustBench T01-T09 classification, including detection of .pyc bytecode bypasses and charset smuggling., MCP Server Scan: Inspects MCP servers for threats such as tool poisoning, credential exfiltration and command injection, with tool whitelisting to prevent remote code execution during dynamic scanning., AI Infrastructure Vulnerability Scanning: Checks deployed AI components against a library that has grown to roughly 130 components and over 2,000 CVE rules, covering frameworks such as llama.cpp., Jailbreak Evaluation: Runs single-turn jailbreak operators plus multi-turn attack techniques including Many-Shot, PAIR, GOAT and ActorAttack to measure a model's resistance., Agent Scan with OWASP Coverage: Assesses running agents using OWASP-derived skills and web exfiltration detection, with a dedicated agent red team skill for comprehensive assessment. to help users with Pre-Deployment Agent Audit: Scan an internally built agent and its skill bundle for prompt injection, exfiltration and privilege risks before it is released to staff., MCP Supply Chain Review: Vet third-party MCP servers for tool poisoning and credential exfiltration before connecting them to production assistants., CI/CD Security Gate: Run skill-scan as a standalone CLI on every pull request so risky agent skills fail the build rather than shipping., Model Safety Benchmarking: Measure how a deployed LLM holds up against single and multi-turn jailbreak techniques before and after guardrail changes., AI Infrastructure Patch Triage: Inventory AI serving components and match them against the CVE rule library to prioritise which hosts need patching..
Key features include Agent Skills Scan: Audits agent skill packages against a nine-category risk taxonomy aligned with the public SkillTrustBench T01-T09 classification, including detection of .pyc bytecode bypasses and charset smuggling., MCP Server Scan: Inspects MCP servers for threats such as tool poisoning, credential exfiltration and command injection, with tool whitelisting to prevent remote code execution during dynamic scanning., AI Infrastructure Vulnerability Scanning: Checks deployed AI components against a library that has grown to roughly 130 components and over 2,000 CVE rules, covering frameworks such as llama.cpp., Jailbreak Evaluation: Runs single-turn jailbreak operators plus multi-turn attack techniques including Many-Shot, PAIR, GOAT and ActorAttack to measure a model's resistance., Agent Scan with OWASP Coverage: Assesses running agents using OWASP-derived skills and web exfiltration detection, with a dedicated agent red team skill for comprehensive assessment..
A.I.G (AI Infra Guard) is useful for anyone interested in Pre-Deployment Agent Audit: Scan an internally built agent and its skill bundle for prompt injection, exfiltration and privilege risks before it is released to staff., MCP Supply Chain Review: Vet third-party MCP servers for tool poisoning and credential exfiltration before connecting them to production assistants., CI/CD Security Gate: Run skill-scan as a standalone CLI on every pull request so risky agent skills fail the build rather than shipping., Model Safety Benchmarking: Measure how a deployed LLM holds up against single and multi-turn jailbreak techniques before and after guardrail changes., AI Infrastructure Patch Triage: Inventory AI serving components and match them against the CVE rule library to prioritise which hosts need patching..
A.I.G (AI Infra Guard) is free to use.
Visit https://github.com/Tencent/AI-Infra-Guard to sign up and explore A.I.G (AI Infra Guard).
Compare A.I.G (AI Infra Guard): vs nodeterm · vs Trama · vs Agents Never Sleep · vs Port Radar for macOS