AI Briefing
KOSign in

Tencent Releases A.I.G, an Open-Source Red-Team Platform for Integrated AI Infrastructure, MCP, and Agent Auditing

·2026.10.05 11:30

Key point

An Apache-2.0 licensed tool that automates vulnerability checks across layers, from infrastructure to model jailbreaking.

1 / 2

Details

Tencent Zhuque Lab has released A.I.G (AI-Infra-Guard), an open-source red-team platform that audits AI infrastructure, MCP servers, agents, and models by layer. Distributed under the Apache-2.0 license, the tool adopts a 'layer-paradigm matching' strategy, distinguishing detection methods by using rule matching for infrastructure and LLM-based attack testing for models.

Key Audit Targets and Methods

  • AI Infrastructure Scan: Inputting URLs/IPs/CIDRs of running services analyzes HTTP responses to identify components and versions, then cross-references them with CVE rules. It supports vLLM, Ollama, Triton Inference Server, LangChain, Dify, and others.
  • MCP Server/Skill Scan: Inputting a GitHub URL or source code allows an LLM agent to read the code and perform static and dynamic audits. It follows 13 rules, including credential exposure, and the SkillTrustBench classification system.
  • Agent Scan: Targets running agents such as Dify and Coze, detecting vulnerabilities through multi-turn black-box conversations and mapping them to the OWASP Top 10 for Agentic Applications.
  • Jailbreak Evaluation: Sends variations of attack technique prompts to model APIs and scores them using a judge model. It includes 17 built-in datasets, such as AdvBench and JailBench.

Benchmark Performance and Caveats

In evaluations based on SkillTrustBench, Claude Opus 4.6 achieved the highest performance with an F1 score of 0.9848, followed by GLM 5.1, Gemini 3.5 Flash, and others. However, since these are self-measured results by the same team that created the benchmark, it is recommended to conduct direct comparative validation using internal samples during actual deployment. Additionally, the system prompt is configured to treat tool responses as data to prevent attacks that deceive the scanner itself.

Installation and Security Considerations

It runs in environments with Docker 20.10 or higher and requires an OpenAI-compatible LLM API key. As there is no authentication feature, deployment on public networks is prohibited, and local binding (127.0.0.1) or firewall configuration is required. Worker containers require SYS_ADMIN privileges and the seccomp:unconfined setting.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.