METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

AI GlossaryAWords you meet while using AI

AI-Infra-Guard

An open-source security scanner released on GitHub by Tencent's Zhuque Lab to check AI models, agents, and MCP servers for vulnerabilities.

In plain words

AI-Infra-Guard (also written A.I.G) is a security-checking tool built by Zhuque Lab, a unit under Tencent's security division, and released for free on GitHub. It scans through the various parts that power an AI system and lists any hidden weaknesses it finds.

Just as inspecting a building means checking the foundation, doors, and plumbing separately, this tool breaks AI systems down into five areas to examine: the core program that handles conversations, the wrapper program that directs it to do tasks, the auxiliary tools it calls on, the channels those tools use to pass messages to each other, and finally the live services actually running in production. Think of it as a checklist a company runs through to make sure everything is locked down before launching a new AI service.

As AI systems increasingly create files, schedule tasks, and call external tools, the range of things that can be attacked has expanded from just the core program to the whole surrounding ecosystem of components. Rather than reacting after something goes wrong, this tool is built for ongoing, routine checks.

How it shows up in the news

The article introduces 'AI-Infra-Guard (A.I.G)' as a tool released by Tencent's Zhuque Lab on GitHub under the Apache 2.0 license. Despite the name sounding like a piece of hardware security gear for data centers, it's actually a software scanning program you install and run. It was developed by Zhuque Lab, part of Tencent, and is distributed via GitHub.

Try it yourself

After launching A.I.G with the installation script, open the address it provides in a browser to bring up the scanning interface. If the service you want to check is actually running, enter its network address to start a scan; to inspect a tool-connection channel (an MCP server), you can either enter a remote address or upload a zipped copy of the source code. However, according to the source material, there's no access verification mechanism yet, so you should not install this on anything left exposed to the outside.

See also

Stories using this term

Browse every entry