@Ryrenz highlights Tencent Zhuque Lab’s open-source AI-Infra-Guard (github.com/Tencent/AI-Infra-Guard): a full-stack AI red-team/scanner with 146+ AI components and 2000+ CVE rules (a recent drop added 155 rules across 40+ components). Beyond infra such as n8n, vLLM, MLflow, and LangFlow, it scans MCP servers and Agent Skills for prompt-injection and unauthorized file-read risks. Apache-2.0; intended for internal use and currently has no auth gate.
Key Takeaways
- ✓Scans AI app stacks for known CVEs across components like n8n, vLLM, MLflow, and LangFlow.
- ✓Also scans MCP servers and Agent Skills for prompt injection and unauthorized file reads.
- ✓Apache-2.0 from Tencent Zhuque Lab; internal-use positioning with no auth—do not expose publicly.
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.