AI Briefing
KO

AI-Infra-Guard: 2000 CVEs and MCP & Agent Vulnerabilities in One Go

Tencent/AI-Infra-Guard

·2026.08.20 19:59

This is a red team platform that provides integrated diagnostics for security vulnerabilities in AI infrastructure and agent workflows. It identifies over 2000 CVE vulnerabilities across more than 100 AI frameworks, including Ollama, vLLM, and ComfyUI. Beyond simple code scanning, it assesses the security posture of the AI infrastructure itself.

It offers precise security analysis for MCP servers and agent skills. It detects 14 major risk categories, such as tool poisoning, credential leakage, and command injection, performing scans via two methods: source code and remote URLs. It also evaluates the security of agent workflows running on various platforms, such as Dify and Coze.

The prompt security assessment feature simulates four types of multi-turn jailbreak attacks: Many-Shot, PAIR, GOAT, and ActorAttack. The aig-skill-scan tool for auditing agent skill security covers nine risk categories aligned with the SkillTrustBench T01~T09 classification system. It achieves an F1 score of 0.9848 based on the Claude Opus 4.6 model.

It is suitable for enterprises and individual developers to proactively check security risks in internal AI systems. Due to insufficient authentication mechanisms for public network deployment, it is recommended for use in internal environments only. It supports Docker-based deployment and can be integrated into CI/CD pipelines for continuous security auditing.

GitHub
GitHub repository

Tencent/AI-Infra-Guard

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

Python

This introduction was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report errors, attribution issues, or removal requests via Contact.