Zero Day Room
Live
Vulnerabilities

Tencent's Zhuque Lab releases AI-Infra-Guard

Zhuque Lab at Tencent has released AI-Infra-Guard, an open-source scanner that checks AI infrastructure services against known CVEs, evaluates MCP servers

Zhuque Lab at Tencent has released AI-Infra-Guard, an open-source scanner that checks AI infrastructure services against...

Tencent's Zhuque Lab has built and released AI-Infra-Guard, an open-source security scanner designed for AI systems. The tool fingerprints running AI services like Ollama, vLLM, and ComfyUI, checking them against a database of more than 1,600 known CVEs.

According to its developers, the platform also inspects Model Context Protocol (MCP) servers and agent skills across 14 categories of risk and runs jailbreak evaluations against a target AI model. The scanner is already in use by several major Chinese firms, including ICBC, China Merchants Bank, China Telecom, Lenovo, vivo, and Bilibili.

Scanner Components and False Positives

The platform operates on two layers. One layer handles straightforward CVE version-matching based on fingerprint accuracy. The other involves interpretation, specifically for evaluating agent skills. To check a skill, the platform asks a language model to judge whether it appears malicious.

This judgment is scored against SkillTrustBench, a public dataset containing 5,520 human-labeled samples across nine risk categories. The false positive rate for these evaluations varies significantly depending on the language model used for the judging.

Model Judgment ScenarioFalse Positive Rate
Low end (clean skill flagged)~1.20%
High end (wasteful flag)~18.67%

The AI-Infra-Guard team stated that "CVE version-matching isn't intent-based at all," noting that "FPR there is purely a function of fingerprint accuracy."

Mitigating Indirect Prompt Injection

A core function of the scanner involves reading files and tool descriptions that could be controlled by a hostile server. This makes it vulnerable to indirect prompt injection, where malicious instructions are hidden within content the model reads. Release version 4.1.9 introduced hardening measures for the scanning agents against this technique.

The team told Help Net Security that the mitigation involves structural separation in the prompt. "File/tool content that gets read is placed into a dedicated, explicitly-delimited text block in the prompt, structurally separated from instructions, rather than mixed inline. The scanning agent is told to treat that block as data to analyze, never as commands to follow," they explained.

They caution that this move "cuts naive-to-moderate injection significantly," but emphasize it is "a mitigation, not a formal guarantee." The team added, "we don't claim it's unbreakable, and we'd say that about any LLM-driven agent." They advise defenders to treat a clean scan result as merely one input, not a full security clearance.

Security and Deployment Warning

The open-source build of AI-Infra-Guard currently lacks any built-in authentication mechanism. The repository carries a clear warning against deploying the platform directly on the public internet. This creates a paradox: a tool built to identify exposed AI services must itself not be exposed.

"AI-Infra-Guard is a single-operator tool by design," the team said. "No login, no RBAC."

Zhuque Lab's recommended solution is to implement access controls externally. The documented setup involves placing a reverse proxy like nginx with Basic Authentication or an IP allowlist in front of the scanner, supplemented by standard firewall rules. A team that deploys the scanner without this external login layer is effectively running a vulnerability scanner that holds the API keys for every model it tests, accessible to anyone who can reach its network port. AI-Infra-Guard is available for free on GitHub.

Related coverage

More from Vulnerabilities