{
  "schema_version": "1.1",
  "id": "archive:https://github.com/Tencent/AI-Infra-Guard",
  "slug": "ai-infra-guard-0msih50",
  "url": "https://feed7.dev/p/ai-infra-guard-0msih50",
  "title": "Tencent/AI-Infra-Guard",
  "why_included": "AI-Infra-Guard packages skill, MCP, agent, infrastructure, and jailbreak scans into one self-hosted red-team platform. The practical warning: it has no authentication and must stay off public networks.",
  "summary": "AI-Infra-Guard scans agent skills, MCP servers, running AI infrastructure, and jailbreak behavior. Version **4.5.2** added bytecode-bypass and charset-smuggling checks, dynamic-mode MCP tool whitelisting, and a library of **2,000+ CVE rules**.",
  "practical_implication": "Add its standalone skill, MCP, or agent scanners to CI when your agent stack accepts third-party extensions or exposes tools. Live infrastructure scans fingerprint services such as vLLM and ComfyUI, while source scans accept repositories or archives.",
  "agent_context": "AI-Infra-Guard scans agent skills, MCP servers, running AI infrastructure, and jailbreak behavior. Version **4.5.2** added bytecode-bypass and charset-smuggling checks, dynamic-mode MCP tool whitelisting, and a library of **2,000+ CVE rules**.\n\nAdd its standalone skill, MCP, or agent scanners to CI when your agent stack accepts third-party extensions or exposes tools. Live infrastructure scans fingerprint services such as vLLM and ComfyUI, while source scans accept repositories or archives.\n\nThe self-hosted platform **has no authentication mechanism**, so it should not be exposed publicly. Its broad rule count and reported SkillTrustBench score describe coverage, but the material does not establish false-positive rates on a builder's own stack.",
  "source": {
    "name": "GitHub",
    "url": "https://github.com/Tencent/AI-Infra-Guard",
    "published_at": null
  },
  "source_class": "tool",
  "content_type": "GitHub Repo",
  "layer": "infra",
  "domains": [
    "security",
    "coding"
  ],
  "topics": [
    "mcp",
    "skills",
    "agent-evals"
  ],
  "verification": {
    "status": "needs_review",
    "label": "Needs Review",
    "method": "unverified",
    "verified_at": null
  },
  "uncertainty": [
    "The self-hosted platform **has no authentication mechanism**, so it should not be exposed publicly. Its broad rule count and reported SkillTrustBench score describe coverage, but the material does not establish false-positive rates on a builder's own stack."
  ],
  "connected_context": {
    "meaning": "This adds a concrete security gate for the expanding skill-and-MCP supply chain, covering packaged extensions, live services, and adversarial behavior rather than relying on format validation or functional evals alone. It confirms that portable agent components require CI and runtime scrutiny, but its rule counts and reported benchmark do not establish local precision, and the unauthenticated platform creates its own deployment boundary.",
    "corpus_size": 542,
    "generated_at": "2026-08-23T10:07:02.670Z",
    "connections": [
      {
        "title": "We Vetted 2000 AI Skills Before They Reached Developers — Lucas Palma, Nubank",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=iKQ78wyJEXU",
        "feed7_url": "https://feed7.dev/p/we-vetted-2000-ai-skills-before-they-reached-developers-lucas-palma-nuba-0k4ehkz",
        "reason": "Nubank’s marketplace process supplies the governance workflow around this scanner category: local and CI checks feed distribution gates and vulnerability management."
      },
      {
        "title": "cursor/plugins",
        "source_name": "GitHub",
        "source_url": "https://github.com/cursor/plugins",
        "feed7_url": "https://feed7.dev/p/plugins-0vuoqp2",
        "reason": "Cursor’s ability to bundle skills, rules, MCP servers, and workflows defines the third-party extension surface that AI-Infra-Guard is designed to inspect."
      },
      {
        "title": "Don't Ship Skills Without Evals — Philipp Schmid, Google DeepMind",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=0vphxNt4wyk",
        "feed7_url": "https://feed7.dev/p/don-t-ship-skills-without-evals-philipp-schmid-google-deepmind-0fuh3ko",
        "reason": "Skill regression evals complement security scanning by testing triggering and outputs across real harnesses; neither functional evaluation nor vulnerability rules substitute for the other."
      },
      {
        "title": "The Regression Tax: Decomposing Why Skills Help and Hurt LLM Agents",
        "source_name": "arXiv",
        "source_url": "https://arxiv.org/abs/2607.22520v1",
        "feed7_url": "https://feed7.dev/p/2607-22520v1-0mz9wnf",
        "reason": "The Regression Tax identifies behavioral failures that a security scanner may not catch, so installation gates also need separate measurements of gains, regressions, grounding, and verification."
      }
    ]
  },
  "lifecycle": "Current",
  "published_at": null,
  "modified_at": null,
  "supersedes": [],
  "expires_at": null,
  "formats": {
    "html": "https://feed7.dev/p/ai-infra-guard-0msih50",
    "json": "https://feed7.dev/p/ai-infra-guard-0msih50.json",
    "markdown": "https://feed7.dev/p/ai-infra-guard-0msih50.md"
  }
}