aicoolies logo
AI-Infra-Guard logo

AI-Infra-Guard

AI red teaming and infrastructure security scanner by Tencent

Share
open-sourceOpen Source
Visit Website →

AI-Infra-Guard is Tencent's open-source AI security platform providing one-click evaluation of AI infrastructure risks across five modules. It covers insecure config detection, multi-agent workflow evaluation, MCP server scanning across 14 risk categories, vulnerability scanning for 55+ AI frameworks with 1,000+ CVE mappings, and jailbreak evaluation for prompt robustness. Deployable via Docker with academic backing from Peking and Fudan Universities.

AI-Infra-Guard is Tencent's open-source security platform that performs comprehensive red teaming and vulnerability assessment of AI infrastructure through five specialized scanning modules. ClawScan detects insecure configurations and known CVEs in AI deployment stacks, Agent Scan evaluates security risks in multi-agent workflows, MCP and Skills Scan identifies vulnerabilities across 14 major security risk categories in model serving configurations, the Infrastructure Vulnerability Scanner covers 55+ AI framework components with mappings to over 1,000 CVEs, and Jailbreak Evaluation tests prompt robustness against adversarial inputs.

The platform takes a holistic approach to AI security that goes beyond traditional application security tools. Rather than treating AI systems as standard web applications, AI-Infra-Guard understands the unique attack surfaces of machine learning infrastructure including model poisoning vectors, inference endpoint exposures, supply chain vulnerabilities in model dependencies, and weaknesses in agent orchestration layers. Each scanning module produces actionable findings with severity ratings and remediation guidance specific to AI deployment patterns.

Developed in collaboration with researchers from Peking University and Fudan University, AI-Infra-Guard can be deployed via Docker for one-click installation and assessment. The project has attracted 3,400 GitHub stars and maintains an actively updated vulnerability database with the latest release being v4.1.3. The Apache 2.0 licensed tool integrates with OpenClaw through its aig-scanner skill, enabling automated security assessments as part of continuous integration pipelines for teams deploying AI systems at scale.

Pricing

Free and open source under Apache 2.0 license

Platforms

Docker, Python, Linux

Categories

Tags

Use Cases

Alternatives

Related Tools

Traceway logo

Traceway

OpenTelemetry-native observability with AI tracing, logs, traces, metrics, and session replay — self-hosted in 90 seconds.

Traceway is an open-source, OpenTelemetry-native observability platform that combines logs, traces, metrics, exceptions, session replay, and AI tracing in a single self-hosted system. MIT licensed with no open-core restrictions, it deploys in 90 seconds via Docker Compose and accepts OTLP/HTTP from any OTel SDK without a Collector or per-language vendor SDK.

open-sourceOpen Source
Judgeval logo

Judgeval

Open-source post-building layer for agents — tracing, evals, and online monitoring

Judgeval is the open-source post-building layer for AI agents from Judgment Labs, providing OpenTelemetry-based tracing, hosted and custom evaluation scorers, and online behavior monitoring for LLM-powered applications. Instrument any function with a single decorator, score live production traffic against faithfulness and instruction-adherence checks, and feed real-world failures back into reinforcement learning or supervised fine-tuning loops.

open-sourceOpen Source
TraceRoot logo

TraceRoot

Open-source observability and self-healing layer for AI agents

TraceRoot is a YC S25-backed open-source observability platform purpose-built for AI agents and LLM apps. It combines OpenTelemetry-compatible tracing with an agentic debugging runtime that reads your source code, correlates failures with recent commits, and proposes fix PRs automatically. BYOK support spans seven LLM providers; the entire stack runs self-hosted via Docker Compose, with TraceRoot Cloud available for managed deployments.

open-sourceOpen Source
OpenSRE logo

OpenSRE

Open-source toolkit for building AI SRE incident response agents

OpenSRE is an open-source Python toolkit from Tracer Cloud for building AI SRE agents that investigate and respond to production incidents. It ships with connectors to Prometheus, Grafana, Kubernetes and incident platforms, plus a simulation harness that replays past incidents so teams can benchmark agent accuracy before trusting it on live pager rotations.

open-sourceOpen Source
Evolver logo

Evolver

Self-evolution engine for AI agents with auditable updates

Evolver is an open-source self-evolution engine for AI agents that turns run logs into auditable, reviewable updates via its Genome Evolution Protocol. Instead of ad hoc prompt tweaking, teams collect traces and Evolver proposes versioned diffs to prompts, tools and workflows that engineers can approve, reject or roll back like code.

open-sourceOpen Source
CodeBurn logo

CodeBurn

See where your AI coding tokens actually go

Open-source TUI dashboard and CLI that shows where your AI coding tokens actually go, broken down by task type, tool, model, MCP server, and project. CodeBurn reads local session data directly from Claude Code, Codex, Cursor, OpenCode, Pi, and GitHub Copilot — no wrapper, proxy, or API keys — and layers on one-shot success rates so you can see whether the AI nails work first try or burns budget on edit/test/fix retries. Ships with a macOS menu bar widget and CSV/JSON export.

freeOpen Source