What happened
Tencent's Zhuque Lab released AI-Infra-Guard (A.I.G) v4.6.x in late Sept 2026 — an Apache-2.0 open-source AI red-teaming platform covering five layers: live AI-infra CVE scanning (146 components, 2000+ CVE rules), MCP-server static scanning, agent-skill auditing (SkillTrustBench T01-T09), agent runtime workflow eval (Dify/Coze) and LLM jailbreak/API auditing with multi-probe detection.
Why it matters
It is one of the broadest free, self-hosted AI-stack scanners available — spanning infra, MCP supply chain, agent skills and jailbreaks in one tool — giving enterprise security teams and researchers an immediately usable red-team/due-diligence capability that would otherwise cost vendor seats; wide OSS reach.
Applicability
Security teams and AppSec/MLSecOps groups self-hosting vLLM/Ollama/MCP/agent stacks should trial A.I.G for pre-deployment scanning and continuous self-assessment; mix in other tools for zero-days and runtime dynamic evasion.