AI-Infra-Guard: Open-Source Security Scanner for AI Systems
Help Net Security, Wednesday, September 9th, 2026
Tencent's open-source AI-Infra-Guard scans AI services, MCP servers, and agent skills, but lacks built-in authentication.
Tencent Zhuque Lab's AI-Infra-Guard fingerprints AI services such as Ollama, vLLM, and ComfyUI against more than 1,600 CVEs, inspects MCP servers and agent skills across 14 risk categories, and runs jailbreak evaluations.
Its LLM-based skill checks show false positive rates from 1.20% to 18.67% on SkillTrustBench, depending on the judging model. Release 4.1.9 hardened scanning agents against indirect prompt injection, though the team calls it a mitigation, not a guarantee.
The tool has no login or RBAC, so the team recommends a reverse proxy and firewall rules.