Tencent/AI-Infra-Guard

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

About the project

AI-Infra-Guard is an AI security red-teaming platform that scans agents, skills, MCP servers, and AI infrastructure and evaluates LLM jailbreak resistance. It is used to identify security risks and vulnerabilities in AI systems. Catalogue add-ons support its scanning and evaluation workflows.

This repository also configures its own agents. See what AI-Infra-Guard tells them →

6.2kStars on the repository
21Mods indexed here, across every type
todayLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect agentic supply-chain risks: compromised dependencies, malicious plugins/tools/models, and untrusted update sources.

not rated 6.2k +48 today A SkillSpector: warn 0 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect privilege escalation and unauthorized access via dialogue. Use when the agent has roles, admin functions, or multi-user data.

not rated 6.2k +48 today A SkillSpector: pass 30 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows.

not rated 6.2k +48 today A SkillSpector: pass 26 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect sensitive information disclosure via escalating dialogue probes. Covers system prompt extraction, credential/API key leakage, PII, and internal configuration exposure.

not rated 6.2k +48 today A SkillSpector: warn 34 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect direct prompt injection or instruction override via user message (no external content). Focuses on system/role override attempts.

not rated 6.2k +48 today B SkillSpector: warn 30 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code needs its repo ✓ vendor

Detect unsafe file handling and path traversal in upload/save/extract flows. Focuses on user-controlled paths or filenames, not data leakage.

not rated 6.2k +48 today A SkillSpector: warn 35 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect hardcoded secrets in code or configuration accessible to the target agent. Focuses on secrets embedded in source, configs, or IaC, not runtime leaks.

not rated 6.2k +48 today A SkillSpector: warn 38 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect social engineering, deceptive responses, false assurances, or prompts that induce unsafe user actions.

not rated 6.2k +48 today A SkillSpector: warn 27 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect indirect prompt injection (goal hijack). Instructions hidden in "external" content (documents, RAG, web) that the agent processes. Use when the agent has document/RAG/web/file input.

not rated 6.2k +48 today A SkillSpector: warn 48 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect persistent instruction injection or long-term memory poisoning. Focus on writing/retaining hostile instructions for future tasks, not data leakage.

not rated 6.2k +48 today A SkillSpector: warn 33 tokens original Apache-2.0

owasp-asi

12

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

OWASP Top 10 for Agentic Applications 2026 (ASI) classification framework. Use for mapping security findings to standardized risk categories.

not rated 6.2k +48 today A SkillSpector: pass 33 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect tool misuse and unexpected code execution via dialogue testing. Use when the agent exposes file, code-execution, or network tools.

not rated 6.2k +48 today A ✓ AI review SkillSpector: warn 32 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude Code ✓ vendor

Detect data exfiltration via URL path encoding and chained webfetch navigation. Covers fake trusted UI injection, letter-level URL path exfiltration, and multi-hop navigation hijacking. Use when the agent has web/URL fetch capability and stores user memory or personal context.

not rated 6.2k +48 today A SkillSpector: warn 61 tokens original Apache-2.0

aig-agent-redteam

16

Tencent/AI-Infra-Guard

Skill Claude CodeCodex needs its repo ✓ vendor

A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.

not rated 6.2k +48 today A SkillSpector: pass 164 tokens original Apache-2.0

aig-scanner

17

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard. Uses built-in exec + Python script, no plugin required. Requires AIGBASEURL to be configured. Triggers on: scan AI service, AI vulnerability scan, scan AI infra…

not rated 6.2k +48 today B SkillSpector: warn 142 tokens original Apache-2.0

edgeone-clawscan

18

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits installed skills, scans skills before installation, and performs a full OpenClaw security health check to prevent data leaks and privacy risks. Backed by Tencent Zhuque…

not rated 6.2k +48 today A Snyk: passSkillSpector: warn 236 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude CodeCodex ✓ vendor

A local static scanner that checks agent-skill files for security risks before they are installed or used. Static analysis examines files without running them.

not rated 6.2k +48 today A SkillSpector: warn 148 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: