Tencent/AI-Infra-Guard
AI-Infra-Guard packages skill, MCP, agent, infrastructure, and jailbreak scans into one self-hosted red-team platform. The practical warning: it has no authentication and must stay off public networks.
AI-Infra-Guard scans agent skills, MCP servers, running AI infrastructure, and jailbreak behavior. Version **4.5.2** added bytecode-bypass and charset-smuggling checks, dynamic-mode MCP tool whitelisting, and a library of **2,000+ CVE rules**.
Add its standalone skill, MCP, or agent scanners to CI when your agent stack accepts third-party extensions or exposes tools. Live infrastructure scans fingerprint services such as vLLM and ComfyUI, while source scans accept repositories or archives.
AI-Infra-Guard scans agent skills, MCP servers, running AI infrastructure, and jailbreak behavior. Version **4.5.2** added bytecode-bypass and charset-smuggling checks, dynamic-mode MCP tool whitelisting, and a library of **2,000+ CVE rules**. Add its standalone skill, MCP, or agent scanners to CI when your agent stack accepts third-party extensions or exposes tools. Live infrastructure scans fingerprint services such as vLLM and ComfyUI, while source scans accept repositories or archives. The self-hosted platform **has no authentication mechanism**, so it should not be exposed publicly. Its broad rule count and reported SkillTrustBench score describe coverage, but the material does not establish false-positive rates on a builder's own stack.
This adds a concrete security gate for the expanding skill-and-MCP supply chain, covering packaged extensions, live services, and adversarial behavior rather than relying on format validation or functional evals alone. It confirms that portable agent components require CI and runtime scrutiny, but its rule counts and reported benchmark do not establish local precision, and the unauthenticated platform creates its own deployment boundary.