Tencent’s Zhuque Lab released AI-Infra-Guard, an open-source scanner for AI systems that fingerprints services like Ollama, vLLM, and ComfyUI, checks thousands of CVEs, inspects MCP servers and agent skills, and tests models for jailbreak resistance. It also highlights risks from indirect prompt injection and notes that the tool should not be exposed directly because the open-source build has no built-in authentication. #AI-Infra-Guard #ZhuqueLab #Ollama #vLLM #ComfyUI #SkillTrustBench #MCP
Keypoints
- AI-Infra-Guard scans AI services and matches them against more than 1,600 known CVEs.
- It inspects MCP servers and agent skills across 14 risk categories.
- The tool runs jailbreak evaluations against target models.
- SkillTrustBench is used to measure false positives in malicious skill detection.
- The open-source build has no authentication and should be protected by a reverse proxy and firewall rules.
Read More: https://www.helpnetsecurity.com/2026/09/09/ai-infra-guard-open-source-security-scanner-ai-systems/