AppSecNews
AI Security Open source Emerging

AI-Infra-Guard

by Tencent

Open source scanner that fingerprints self hosted AI infrastructure components and matches them against known vulnerabilities, with an MCP server analysis mode.

Visit tencent.github.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run AI-Infra-Guard in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current list of fingerprinted components and the size of the vulnerability rule set: verify against project docs
  • MCP analysis and jailbreak evaluation modules: confirm which are present and what they require

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

AI-Infra-Guard scans hosts and URLs for the software that AI teams stand up quickly and then forget about: model servers, inference gateways, notebook environments, workflow builders, vector stores, and orchestration frameworks. Detection works by fingerprinting. Each supported component has a rule file describing how it identifies itself over HTTP, through response headers, body markers, characteristic paths, or a version endpoint. When a fingerprint matches, the scanner resolves the detected version against a bundled set of known vulnerability records and reports what applies.

The second half of the tool looks at Model Context Protocol servers. This mode inspects an MCP server's exposed tools and their descriptions, looking for patterns that indicate risk: tool descriptions that contain instructions aimed at the calling model, tools whose declared purpose does not match what the implementation does, credential handling in tool arguments, and command execution surface. That analysis is model assisted, so it requires a model endpoint of your own, which can be local. The project also ships a prompt injection and jailbreak evaluation component for testing a model endpoint directly.

Where it fits

This is a discovery and assessment tool, run by a security team against internal networks or by a platform team against its own estate. The most useful placement is periodic scanning of environments where experimentation happens, since the problem it addresses is AI services deployed outside change control and left exposed with default settings. The MCP mode fits an intake review: run it before approving a third party MCP server for use by agents that hold real credentials. You need network reachability to the targets and, for the MCP and jailbreak modules, a model to drive the analysis.

Strengths

  • Targets a genuine blind spot: general purpose vulnerability scanners do not carry fingerprints for AI specific components, so these services routinely go unassessed.
  • Fingerprint rules are declarative files, so adding coverage for an internal or newly popular component does not require changing the scanner.
  • MCP tool inspection addresses supply chain risk in agent tooling, which is not covered by traditional dependency scanning.
  • Single binary, so it is quick to run without building a deployment around it.

Limitations

  • Version to vulnerability matching without exploitation produces false positives, and a fingerprinted version string is not proof of an exploitable path.
  • The bundled vulnerability data must be kept current to be worth anything. Stale rules give false confidence.
  • Model assisted MCP analysis is not deterministic. Two runs can disagree, and a well written malicious tool description may read as benign.

Who it suits

Security teams responsible for environments where data scientists and engineers self host AI tooling. Less relevant to organizations that consume only hosted model APIs and run no AI infrastructure of their own.

Used AI-Infra-Guard? Recommend it under your own name and title.

Recommend this tool