Tencent/AI-Infra-GuardPublic

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

AI summary: A comprehensive security framework for auditing and protecting AI infrastructure and large language models.

Stars
6.7K
+84 today
Forks
632
Watchers
49
Open issues
14
Open PRs
27
Contributors
~58
Commits
1.9K
Branches
40

PythonApache-2.0Created Dec 25, 2024Last push 1d agoLatest release v4.6.3+155 stars this week+606 this month

Quick answers

What is AI-Infra-Guard?
A comprehensive security framework for auditing and protecting AI infrastructure and large language models.
What does AI-Infra-Guard do?
AI-Infra-Guard is a robust security testing framework specifically engineered to evaluate and protect AI infrastructure. It provides systematic methodologies and automated tools to audit Large Language Models (LLMs) against a wide array of attack vectors, including prompt injection, jailbreaking, and data exfiltration. The platform helps organizations identify vulnerabilities within their AI deployments before they can be exploited in production. By offering a standardized approach to AI security, it ensures that machine learning models and their surrounding infrastructure remain resilient against adversarial threats.
Who is AI-Infra-Guard for?
This framework is designed for AI security researchers, ML engineers, and enterprise security teams responsible for safeguarding AI infrastructure. It requires a strong understanding of adversarial machine learning.
How do I get started with AI-Infra-Guard?
https://tencent.github.io/AI-Infra-Guard/
How popular is AI-Infra-Guard on GitHub?
Tencent/AI-Infra-Guard has 6,739 stars and 632 forks on GitHub, and gained 155 stars in the last 7 days.
What license does AI-Infra-Guard use?
Tencent/AI-Infra-Guard is released under the Apache-2.0 license.

Star history

since Aug 21, 2026
02K4K6KAug 2026Sep 2026Sep 2026Oct 2026
6.7K stars as of Oct 4, 2026. Measured daily since Aug 21, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
SepOctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-09-28: 4 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 2 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 1 commit2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 1 commit2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 2 commits2025-10-23: 2 commits2025-10-24: 1 commit2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 9 commits2025-10-28: 1 commit2025-10-29: 2 commits2025-10-30: 0 commits2025-10-31: 1 commit2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 2 commits2025-11-04: 2 commits2025-11-05: 1 commit2025-11-06: 1 commit2025-11-07: 0 commits2025-11-08: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 5 commits2025-11-13: 2 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 2 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 1 commit2025-11-26: 2 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 3 commits2025-12-02: 7 commits2025-12-03: 15 commits2025-12-04: 16 commits2025-12-05: 9 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 3 commits2025-12-10: 7 commits2025-12-11: 2 commits2025-12-12: 1 commit2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 2 commits2025-12-16: 3 commits2025-12-17: 0 commits2025-12-18: 1 commit2025-12-19: 1 commit2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 5 commits2025-12-23: 2 commits2025-12-24: 0 commits2025-12-25: 17 commits2025-12-26: 8 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 1 commit2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 1 commit2026-01-03: 0 commits2026-01-04: 2 commits2026-01-05: 4 commits2026-01-06: 4 commits2026-01-07: 8 commits2026-01-08: 5 commits2026-01-09: 8 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 6 commits2026-01-14: 3 commits2026-01-15: 13 commits2026-01-16: 4 commits2026-01-17: 4 commits2026-01-18: 0 commits2026-01-19: 4 commits2026-01-20: 7 commits2026-01-21: 6 commits2026-01-22: 7 commits2026-01-23: 2 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 1 commit2026-01-27: 12 commits2026-01-28: 2 commits2026-01-29: 6 commits2026-01-30: 5 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 7 commits2026-02-03: 10 commits2026-02-04: 4 commits2026-02-05: 8 commits2026-02-06: 3 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 6 commits2026-02-10: 3 commits2026-02-11: 3 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 2 commits2026-02-27: 4 commits2026-02-28: 2 commits2026-03-01: 1 commit2026-03-02: 2 commits2026-03-03: 0 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 0 commits2026-03-09: 1 commit2026-03-10: 10 commits2026-03-11: 2 commits2026-03-12: 3 commits2026-03-13: 0 commits2026-03-14: 0 commits2026-03-15: 0 commits2026-03-16: 4 commits2026-03-17: 4 commits2026-03-18: 0 commits2026-03-19: 0 commits2026-03-20: 11 commits2026-03-21: 0 commits2026-03-22: 0 commits2026-03-23: 9 commits2026-03-24: 0 commits2026-03-25: 18 commits2026-03-26: 5 commits2026-03-27: 10 commits2026-03-28: 3 commits2026-03-29: 0 commits2026-03-30: 4 commits2026-03-31: 2 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 12 commits2026-04-04: 0 commits2026-04-05: 2 commits2026-04-06: 1 commit2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 4 commits2026-04-10: 13 commits2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 2 commits2026-04-14: 19 commits2026-04-15: 9 commits2026-04-16: 3 commits2026-04-17: 9 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 4 commits2026-04-21: 6 commits2026-04-22: 9 commits2026-04-23: 9 commits2026-04-24: 1 commit2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 0 commits2026-04-28: 0 commits2026-04-29: 0 commits2026-04-30: 1 commit2026-05-01: 0 commits2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 0 commits2026-05-05: 0 commits2026-05-06: 0 commits2026-05-07: 3 commits2026-05-08: 0 commits2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 1 commit2026-05-12: 1 commit2026-05-13: 2 commits2026-05-14: 33 commits2026-05-15: 1 commit2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 8 commits2026-05-20: 2 commits2026-05-21: 3 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 0 commits2026-05-26: 1 commit2026-05-27: 0 commits2026-05-28: 3 commits2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 0 commits2026-06-02: 2 commits2026-06-03: 1 commit2026-06-04: 3 commits2026-06-05: 0 commits2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 4 commits2026-06-09: 1 commit2026-06-10: 0 commits2026-06-11: 4 commits2026-06-12: 2 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 0 commits2026-06-16: 0 commits2026-06-17: 2 commits2026-06-18: 4 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 11 commits2026-06-22: 3 commits2026-06-23: 2 commits2026-06-24: 3 commits2026-06-25: 7 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 10 commits2026-06-30: 10 commits2026-07-01: 7 commits2026-07-02: 5 commits2026-07-03: 4 commits2026-07-04: 0 commits2026-07-05: 0 commits2026-07-06: 4 commits2026-07-07: 2 commits2026-07-08: 3 commits2026-07-09: 0 commits2026-07-10: 0 commits2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 3 commits2026-07-14: 0 commits2026-07-15: 12 commits2026-07-16: 0 commits2026-07-17: 2 commits2026-07-18: 0 commits2026-07-19: 0 commits2026-07-20: 0 commits2026-07-21: 5 commits2026-07-22: 1 commit2026-07-23: 3 commits2026-07-24: 9 commits2026-07-25: 0 commits2026-07-26: 0 commits2026-07-27: 3 commits2026-07-28: 2 commits2026-07-29: 1 commit2026-07-30: 5 commits2026-07-31: 3 commits2026-08-01: 1 commit2026-08-02: 0 commits2026-08-03: 0 commits2026-08-04: 3 commits2026-08-05: 2 commits2026-08-06: 1 commit2026-08-07: 2 commits2026-08-08: 0 commits2026-08-09: 0 commits2026-08-10: 2 commits2026-08-11: 1 commit2026-08-12: 1 commit2026-08-13: 1 commit2026-08-14: 1 commit2026-08-15: 1 commit2026-08-16: 0 commits2026-08-17: 6 commits2026-08-18: 13 commits2026-08-19: 11 commits2026-08-20: 1 commit2026-08-21: 4 commits2026-08-22: 2 commits2026-08-23: 1 commit2026-08-24: 0 commits2026-08-25: 5 commits2026-08-26: 11 commits2026-08-27: 1 commit2026-08-28: 1 commit2026-08-29: 0 commits2026-08-30: 1 commit2026-08-31: 2 commits2026-09-01: 3 commits2026-09-02: 0 commits2026-09-03: 2 commits2026-09-04: 1 commit2026-09-05: 2 commits2026-09-06: 0 commits2026-09-07: 0 commits2026-09-08: 2 commits2026-09-09: 1 commit2026-09-10: 5 commits2026-09-11: 4 commits2026-09-12: 0 commits2026-09-13: 0 commits2026-09-14: 1 commit2026-09-15: 6 commits2026-09-16: 4 commits2026-09-17: 6 commits2026-09-18: 1 commit2026-09-19: 0 commits2026-09-20: 4 commits2026-09-21: 0 commits2026-09-22: 0 commits2026-09-23: 0 commits2026-09-24: 2 commits2026-09-25: 0 commits2026-09-26: 0 commits
826 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Very active

    826 commits in 52 weeks

  • Well documented

    High community health score

  • Permissive license

    Apache-2.0

  • Continuous integration

    Automated checks passing

  • Repeat trending

    7 trending appearances

What AI-Infra-Guard does

AI-Infra-Guard is a robust security testing framework specifically engineered to evaluate and protect AI infrastructure. It provides systematic methodologies and automated tools to audit Large Language Models (LLMs) against a wide array of attack vectors, including prompt injection, jailbreaking, and data exfiltration. The platform helps organizations identify vulnerabilities within their AI deployments before they can be exploited in production. By offering a standardized approach to AI security, it ensures that machine learning models and their surrounding infrastructure remain resilient against adversarial threats.

This framework is designed for AI security researchers, ML engineers, and enterprise security teams responsible for safeguarding AI infrastructure. It requires a strong understanding of adversarial machine learning.

  • Automated vulnerability auditing: Systematically scans LLMs and AI infrastructure for known security flaws and weaknesses.
  • Adversarial attack simulation: Tests model resilience by executing complex prompt injection and jailbreak scenarios.
  • Comprehensive reporting: Generates detailed security assessments highlighting specific vulnerabilities and recommended mitigations.
  • Data privacy protection: Evaluates models for potential data leakage to ensure sensitive training data is not exposed.
  • Framework agnostic testing: Supports the security evaluation of various AI models regardless of their underlying architecture.

Where teams use it

LLM security auditing

Conduct thorough security assessments on deployed Large Language Models to identify prompt injection vulnerabilities.

Adversarial resilience testing

Simulate sophisticated attacks against AI infrastructure to ensure models do not generate harmful or restricted content.

Data leakage prevention

Evaluate AI systems to guarantee they do not inadvertently exfiltrate or reveal sensitive data embedded during training.

Compliance verification

Ensure enterprise AI deployments meet strict security and privacy standards before being released to production environments.

Getting started: https://tencent.github.io/AI-Infra-Guard/

README

main branch

A.I.G

📖 Documentation  |  🌐 🇨🇳 中文 · 🇯🇵 日本語 · 🇪🇸 Español · 🇩🇪 Deutsch · 🇫🇷 Français · 🇰🇷 한국어 · 🇧🇷 Português · 🇷🇺 Русский

GitHub stars GitHub downloads docker pulls Release Ask DeepWiki

EdgeOne ClawScan EdgeOne Skill Scanner AIG Scanner

OpenClaw Recommended

Tencent%2FAI-Infra-Guard | Trendshift  Tencent%2FAI-Infra-Guard | blackhat  Tencent%2FAI-Infra-Guard | awesome-deepseek-integration


🚀 AI Red Teaming Platform by Tencent Zhuque Lab

A.I.G (AI-Infra-Guard) integrates capabilities such as ClawScan(OpenClaw Security Scan), Agent Scan,AI infra vulnerability scan, MCP Server & Agent Skills scan, and Jailbreak Evaluation, aiming to provide users with the most comprehensive, intelligent, and user-friendly solution for AI security risk self-examination.

We are committed to making A.I.G(AI-Infra-Guard) the industry-leading AI red teaming platform. More stars help this project reach a wider audience, attracting more developers to contribute, which accelerates iteration and improvement. Your star is crucial to us!

Give us a Star


📋 User Feedback Survey

Help us improve A.I.G! Please take 3-5 minutes to fill out our User Feedback Survey. Users who provide high-quality feedback and leave a valid email address will receive an exclusive Tencent souvenir gift.


🚀 What's New

  • 2026-09-17 · v4.6.2 — Vuln library expanded with 155 new CVE rules across 40+ AI components (LangFlow, n8n, PraisonAI, vLLM, llama-cpp, MLflow & more); Skill-Scan accuracy improvements (fewer evidence-free false positives, stall-free streaming); new agent loss-of-control benchmarks (FORGE-Bench, RogueHandoff-20).
  • 2026-09-10 · v4.6.1 — API Checker: expanded model fingerprint coverage (Gemini 2.5/3.1, Gemma 2/3/4, GLM-5.3 & GLM-5.3-Flash); MCP-Scan reliability: flags empty/incomplete scans, preserves security findings during context compaction, surfaces underlying connection errors; corrected mislabeled CVE product names.
  • 2026-08-26 · v4.6.0 — LLM API poisoning detection (multi-probe black-box audit for model substitution & backdoor risks); Agent-Scan v5.0.0 mutation engine refactor; vuln library expanded to 146 AI components & 2000+ CVE rules; MCP/Skill scan stability & compatibility fixes.
  • 2026-08-17 · v4.5.2 — Skill-Scan: .pyc bytecode bypass detection + charset smuggling defense; MCP-Scan: RCE prevention via tool whitelisting in dynamic mode; new SkillJack research project; vuln library expanded to 2000+ CVE rules.
  • 2026-07-30 · v4.5.1 — Jailbreak Evaluation: 4 multi-turn jailbreak attacks (Many-Shot, PAIR, GOAT, ActorAttack); Agent-Scan: 5 new OWASP skills + web-exfiltration detection (10 skills total); MCP-Scan: 4 new security rules

👉 Earlier releases · 🛒 AI Security Skill Market · 🔍 skill-scan CLI · 🔍 mcp-scan CLI · 🔍 agent-scan CLI · 📊 SkillTrustBench

Table of Contents

🚀 Quick Start

🐳 Deploy A.I.G with Docker

Docker RAM Disk Space
20.10 or higher 4GB+ 10GB+
# This method pulls pre-built images from Docker Hub for a faster start
git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
# For Docker Compose V2+, replace 'docker-compose' with 'docker compose'
docker-compose -f docker-compose.images.yml up -d

Once the service is running, you can access the A.I.G web interface at: http://localhost:8088

Use from OpenClaw

You can also call A.I.G directly from OpenClaw chat via the aig-scanner skill.

clawhub install aig-scanner

Then configure AIG_BASE_URL to point to your running A.I.G service.

For more details, see the aig-scanner README.

More installation options

Other Installation Methods

Method 2: One-Click Install Script (Recommended)

# This method will automatically install Docker and launch A.I.G with one command
curl https://raw.githubusercontent.com/Tencent/AI-Infra-Guard/refs/heads/main/docker.sh | bash

Method 3: Build and run from source

git clone https://github.com/Tencent/AI-Infra-Guard.git
cd AI-Infra-Guard
# This method builds a Docker image from local source code and starts the service
# (For Docker Compose V2+, replace 'docker-compose' with 'docker compose')
docker-compose up -d

Note: The AI-Infra-Guard project is positioned as an AI red teaming platform for internal use by enterprises or individuals. It currently lacks an authentication mechanism and should not be deployed on public networks.

For more information, see: https://tencent.github.io/AI-Infra-Guard/?menu=getting-started

⚡ Install aig-skill-scan with a Single Command

Agent Skill security audit tool, easily integrated into enterprise CI/CD pipelines. Vulnerability classification aligns with SkillTrustBench T01–T09 taxonomy. Learn more →

pip install aig-skill-scan

# Set API key via environment variable
export LLM_API_KEY="your-api-key"

# Scan a local Skill project directory
aig-skill-scan --repo /path/to/your/skill \
           -m deepseek-v4-flash \
           --language en \
           -o result.json

Model and API Relay Checker

The checker frontend is deployed separately. Docker deployment keeps the checker APIs available at GET /api/v1/relay/models and POST /api/v1/relay/check/stream; API documentation is available at http://127.0.0.1:8088/api-checker/docs. To run the checker and unified CLI from source:

python3 -m venv services/api_checker/.venv
services/api_checker/.venv/bin/pip install -r services/api_checker/requirements.txt
go build -o ai-infra-guard ./cmd/cli/main.go

export AIG_API_CHECKER_PYTHON="$PWD/services/api_checker/.venv/bin/python"
./ai-infra-guard api-checker list
./ai-infra-guard api-checker audit

See the API Checker integration guide for the Agent-embedded runtime architecture, HTTP API, configuration, and security boundaries.

🌟 Try the Online Pro Version

Experience the Pro version with advanced features and improved performance. The Pro version requires an invitation code and is prioritized for contributors who have submitted issues, pull requests, or discussions, or actively help grow the community. Visit: https://aigsec.ai/.

✨ Features

🔍 aig-skill-scan Performance & Coverage

Performance on SkillTrustBench with different LLMs:

# Model F1 Precision Recall FPR
1 Claude Opus 4.6 0.9848 0.9725 0.9974 0.0663
2 GLM 5.1 0.9836 0.9701 0.9974 0.0723
3 Gemini 3.5 Flash 0.9792 0.9947 0.9641 0.0120
4 Kimi 2.6 0.9780 0.9895 0.9667 0.0241
5 DeepSeek v4 Flash 0.9740 0.9868 0.9615 0.0301

Covers 9 categories of Skill security risks (SkillTrustBench T01–T09):

Layer Risks
A · Instruction & Memory T01 Skill Instruction Hijacking, T02 Memory Poisoning
B · Code Execution T03 Remote Payload Download & Execution, T04 Embedded Malicious Code
C · System Privilege T05 Privilege Escalation & Unauthorized Access, T06 System Persistence
D · Toolchain & Dependencies T07 Tool Hijacking & Spoofing, T08 Insecure Dependencies
E · Skill Code Quality T09 Insecure Coding Practices

For full leaderboard and details, visit SkillTrustBench.

🔬 Security Scanning & Evaluation

Feature More Info
ClawScan(OpenClaw Security Scan) Supports one-click evaluation of OpenClaw security risks. It detects insecure configurations, Skill risks, CVE vulnerabilities, and privacy leakage.
Agent Scan This is an independent, multi-agent automated scanning framework. It is designed to evaluate the security of AI agent workflows. It seamlessly supports agents running across various platforms, including Dify and Coze.
MCP Server & Agent Skills scan It thoroughly detects 14 major categories of security risks. The detection applies to both MCP Servers and Agent Skills. It flexibly supports scanning from both source code and remote URLs.
AI infra vulnerability scan This scanner precisely identifies over 100 AI framework components. It covers more than 2000 known CVE vulnerabilities. Supported frameworks include Ollama, ComfyUI, vLLM, n8n, Triton Inference Server and more.
Jailbreak Evaluation It assesses prompt security risks using carefully curated datasets. The evaluation applies multiple attack methods to test robustness. It also provides detailed cross-model comparison capabilities.
Model and API Relay Checker Model fingerprinting, Claude Signature verification, relay black-box auditing, PAMELA, and Ventor QTest.
💎 Additional Benefits
  • 🖥️ Modern Web Interface: User-friendly UI with one-click scanning and real-time progress tracking
  • 🔌 Complete API: Full interface documentation and Swagger specifications for easy integration
  • 🤖 Agent-Ready: Plug-and-play agent skills on ClawHub — EdgeOne ClawScan, EdgeOne Skill Scanner, and AIG Scanner — seamlessly embed security scanning into any AI agent workflow
  • 🌐 Multi-Language: Chinese and English interfaces with localized documentation
  • 🐳 Cross-Platform: Linux, macOS, and Windows support with Docker-based deployment
  • 🆓 Free & Open Source: Completely free under the Apache 2.0 license

🖼️ Showcase

A.I.G Main Interface

A.I.G Main Page

Plugin Management

Plugin Management


🗺️ Quick Usage Guide

After deployment, open http://localhost:8088 in your browser.

AI Infrastructure Vulnerability Scan

What to enter as the target URL / IP?

The target is the network address of a running AI service you want to scan - not a GitHub URL or source code path. A.I.G connects to the live service and fingerprints it for known CVE vulnerabilities.

Scenario Example target
A locally running vLLM instance http://127.0.0.1:8000
An Ollama server on your LAN http://192.168.1.100:11434
A ComfyUI instance exposed internally http://10.0.0.5:8188
Multiple hosts (one per line) 192.168.1.0/24 (CIDR), 10.0.0.1-10.0.0.20 (range)

Step-by-step: Scan a local vLLM instance

  1. Start vLLM normally (e.g. python -m vllm.entrypoints.api_server --model meta-llama/...)
  2. In the A.I.G web UI, click "AI基础设施安全扫描 / AI Infra Scan"
  3. Enter http://127.0.0.1:8000 (or the IP/port where vLLM is listening)
  4. Click Start Scan - A.I.G will fingerprint the service and match it against 2000+ known CVEs
  5. View the report: component version, matched vulnerabilities, severity, and remediation links

💡 Tip: To scan the nightly build of vLLM specifically, just run that nightly build and point A.I.G at its address. The scanner detects the version automatically.

MCP Server & Agent Skills Scan

Enter either a remote URL (e.g. https://github.com/user/mcp-server) or upload a local source archive - no running instance required.

Jailbreak Evaluation

Configure the target LLM's API endpoint (base URL + API key) in Settings → Model Config, then select a dataset and start the evaluation.


📖 User Guide

Visit our online documentation: https://tencent.github.io/AI-Infra-Guard/

For more detailed FAQs and troubleshooting guides, visit our documentation.

🔧 API Documentation

A.I.G provides a comprehensive set of task creation APIs that support AI infra scan, MCP Server Scan, and Jailbreak Evaluation capabilities.

After the project is running, visit http://localhost:8088/docs/index.html to view the complete API documentation.

For detailed API usage instructions, parameter descriptions, and complete example code, please refer to the Complete API Documentation.

📝 Contribution Guide

The extensible plugin framework​​ serves as A.I.G's architectural cornerstone, inviting community innovation through Plugin and Feature contributions.​

Plugin Contribution Rules

  1. Fingerprint Rules: Add new YAML fingerprint files to the data/fingerprints/ directory.
  2. Vulnerability Rules: Add new vulnerability scan rules to the data/vuln/ directory.
  3. MCP Plugins: Add new MCP security scan rules to the data/mcp/ directory.
  4. Jailbreak Evaluation Datasets: Add new Jailbreak evaluation datasets to the data/eval directory.

Please refer to the existing rule formats, create new files, and submit them via a Pull Request.

Other Ways to Contribute



🛡️ About the Team

This project is led and developed by Tencent Zhuque Lab, part of the Tencent Security Platform Department. Founded in 2019, Tencent Zhuque Lab is a top-tier security research lab focused on real-world offensive and defensive research and frontier technology in the AI security space, covering large model security, AI agent security, AI-empowered security, and AI-generated content detection.

The team has helped major vendors such as NVIDIA, Google, and Microsoft, as well as open-source communities like OpenClaw, Linux, and Hugging Face, fix a large number of high-risk vulnerabilities, and has been publicly acknowledged by them.

We have released open-source AI security products including the AI Red Team Security Testing Platform A.I.G (AI-Infra-Guard) and the Zhuque AI Detection Assistant. Our research has been widely published at top international security and AI conferences such as Black Hat, DEF CON, ICLR, CVPR, NeurIPS, and ACL, and we have authored the book "AI Security: Technology and Practice".

👥 Core Members & Contributions

Role Member Contribution
Head of Tencent Security Platform Department Yong Yang Initiated A.I.G and proposed automated assessment of AI agent loss-of-control risks, guiding the platform's expansion from AI infrastructure vulnerability scanning to agent execution risk, tool misuse, and permission-boundary evaluation.
Head of Tencent Zhuque Lab Xing Zheng Proposed the automated vulnerability-update and benchmark-alignment mechanism, helping AI Infra fingerprints, CVE/GHSA rules, and benchmarks iterate continuously.
Project Lead Nicky Frontier security research, product planning, technical-route decisions, internal and external collaboration, and communications.
Technical Lead Python Overall architecture design, core module development, and version iteration.
Core Contributor Zona Frontend interaction, product experience, community operations, and user-feedback loop.
Core Contributor Fyoung AI Infra vulnerability component fingerprint updates and Benchmark system construction.
Core Contributor Xiangfan Security capability development for Skill risks and agent loss-of-control scenarios.
Core Contributor Elwood Enhancing Agent security scanning capabilities and updating technical reports.
Core Contributor Robert LLM safety assessment and jailbreak-evaluation strategy operations.
Core Contributor Zoe LLM safety assessment, jailbreak evaluation, and model-integration module development.
Contributor Ronin Participated in AI agent security scanning development.
Contributor Rsin Participated in community operations and campaign communications.

🙏 Acknowledgements

🎓 Academic Collaborations

We thank our academic partners for their research contributions and technical support.


Prof. hui Li

Bin Wang

Zexin Liu

Hao Yu

Ao Yang

Zhengxi Lin

Prof. Zhemin Yang

Kangwei Zhong

Jiapeng Lin

Cheng Sheng

👥 Gratitude to Contributing Developers

Thanks to all the developers who have contributed to the A.I.G project.

Keen Lab WeChat Security Fit Security


🤝 Appreciation for Our Users

Thanks to the users from the following organizations and teams for using A.I.G and their valuable feedback.


Tencent DeepSeek Antintl Lenovo ICBC Vivo Oppo Haier Abc 招商银行 中国电信 Bilibili Qunar 蜜雪冰城 IDG kingdee 联通数科 长安汽车 天鹅到家
清华大学 北京大学 南洋理工大学 复旦大学 浙江大学 南京大学 武汉大学 An-Najah National University 西安交通大学 华中科技大学 南开大学 四川大学 Binus University


💬 Join the Community

🌐 Online Discussions

📱 Discussion Community

WeChat Group Discord [link]
WeChat Group discord

📧 Contact Us

For collaboration inquiries or feedback, please contact us at: zhuque@tencent.com

🔗 Recommended Security Tools

If you are interested in code security, check out A.S.E (AICGSecEval), the industry's first repository-level AI-generated code security evaluation framework open-sourced by the Tencent Wukong Code Security Team.



📖 Citation

If you use A.I.G in your research, please cite:

@misc{Tencent_AI-Infra-Guard_2025,
  author={{Tencent Zhuque Lab}},
  title={{AI-Infra-Guard: A Comprehensive, Intelligent, and Easy-to-Use AI Red Teaming Platform}},
  year={2025},
  howpublished={GitHub repository},
  url={https://github.com/Tencent/AI-Infra-Guard}
}

📚 Research & Papers

Research:

  1. "RogueHandoff-20: Measuring Susceptibility to Unsafe Agent Trajectories" — A Docker-based benchmark measuring whether an agent adopts an unsafe trajectory supplied as preceding state, testing susceptibility after exposure to another agent's unsafe strategy. [code]

  2. "FORGE-Bench: A Deterministic Benchmark for Loss of Control in Autonomous Agents" — A deterministic, oracle-based benchmark studying how autonomous agents lose control while pursuing legitimate tasks, evaluating goal pressure, constraint degradation, and unsafe opportunity across 16 domains and 1,800 trajectories. [arXiv] [code]

  3. "DeepSeek Harness Indirect Prompt-Injection Assessment" — Authorized security assessment of DeepSeek Harness against indirect prompt-injection across 14,560 agent runs. [code]

  4. "SkillJack: Persistent Skill Backdoors in Self-Evolving Agents" — Demonstrates how poisoned trajectories can inject persistent backdoors into self-evolving agent skill systems. [code]

Papers:

  1. "Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming" — A comprehensive framework for securing AI agent systems through multi-layer red teaming across infrastructure, supply chain, runtime interaction, and deployment surfaces. [arXiv] [pdf]

  2. "AI-Infra-Guard: An AI Red Teaming Platform" — Black Hat Europe 2025 Arsenal presentation showcasing A.I.G's capabilities and real-world use cases. [pdf]

  3. "MCP Unchained: Compromising The AI Agent Ecosystem Via Its Universal Connector" — Black Hat Europe 2025 talk revealing security risks in the MCP protocol within the AI agent ecosystem. [pdf]

Thanks to the research teams who have cited A.I.G in their academic work (19 papers):

📄 View all 19 cited papers
  1. Chenning Li, Pan Hu, Justin Xu et al. "ADR: An Agentic Detection System for Enterprise Agentic AI Security." arXiv preprint arXiv:2605.17380 (2026). [pdf]

  2. Zhaojiacheng Zhou. "Proteus: A Self-Evolving Red Team for Agent Skill Ecosystems." arXiv preprint arXiv:2605.11891 (2026). [pdf]

  3. Hengkai Ye, Zhechang Zhang, Jinyuan Jia et al. "TRUSTDESC: Preventing Tool Poisoning in LLM Applications via Trusted Description Generation." arXiv preprint arXiv:2604.07536 (2026). [pdf]

  4. Zenghao Duan, Yuxin Tian, Zhiyi Yin et al. "SkillAttack: Automated Red Teaming of Agent Skills through Attack Path Refinement." arXiv preprint arXiv:2604.04989 (2026). [pdf]

  5. Yiheng Huang, Zhijia Zhao, Bihuan Chen et al. "From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers." arXiv preprint arXiv:2604.01905 (2026). [pdf]

  6. Yi Ting Shen, Kentaroh Toyoda, Alex Leung. "MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)." arXiv preprint arXiv:2603.18063 (2026). [pdf]

  7. Yuepeng Hu, Yuqi Jia, Mengyuan Li et al. "MalTool: Malicious Tool Attacks on LLM Agents." arXiv preprint arXiv:2602.12194 (2026). [pdf]

  8. Naen Xu, Jinghuai Zhang, Ping He et al. "FraudShield: Knowledge Graph Empowered Defense for LLMs against Fraud Attacks." arXiv preprint arXiv:2601.22485v1 (2026). [pdf]

  9. Ruiqi Li, Zhiqiang Wang, Yunhao Yao et al. "MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP." arXiv preprint arXiv:2601.07395v1 (2026). [pdf]

  10. Jingxiao Yang, Ping He, Tianyu Du et al. "HogVul: Black-box Adversarial Code Generation Framework Against LM-based Vulnerability Detectors." arXiv preprint arXiv:2601.05587v1 (2026). [pdf]

  11. Teofil Bodea, Masanori Misono, Julian Pritzi et al. "Trusted AI Agents in the Cloud." arXiv preprint arXiv:2512.05951v1 (2025). [pdf]

  12. Yunyi Zhang, Shibo Cui, Baojun Liu et al. "Beyond Jailbreak: Unveiling Risks in LLM Applications Arising from Blurred Capability Boundaries." arXiv preprint arXiv:2511.17874v2 (2025). [pdf]

  13. Bin Wang, Zexin Liu, Hao Yu et al. "MCPGuard: Automatically Detecting Vulnerabilities in MCP Servers." arXiv preprint arXiv:2510.23673v1 (2025). [pdf]

  14. Weibo Zhao, Jiahao Liu, Bonan Ruan et al. "When MCP Servers Attack: Taxonomy, Feasibility, and Mitigation." arXiv preprint arXiv:2509.24272v1 (2025). [pdf]

  15. Ping He, Changjiang Li, et al. "Automatic Red Teaming LLM-based Agents with Model Context Protocol Tools." arXiv preprint arXiv:2509.21011 (2025). [pdf]

  16. Christian Coleman. "Behavioral Detection Methods for Automated MCP Server Vulnerability Assessment." (2025). [pdf]

  17. Yixuan Yang, Daoyuan Wu, Yufan Chen. "MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols." arXiv preprint arXiv:2508.13220 (2025). [pdf]

  18. Yongjian Guo, Puzhuo Liu, et al. "Systematic Analysis of MCP Security." arXiv preprint arXiv:2508.12538 (2025). [pdf]

  19. Zexin Wang, Jingjing Li, et al. "A Survey on AgentOps: Categorization, Challenges, and Future Directions." arXiv preprint arXiv:2508.02121 (2025). [pdf]

📧 If you have used A.I.G in your research or product, or if we have inadvertently missed your publication, we would love to hear from you! Contact us here.

⚖️ License & Attribution

This project is open-sourced under the Apache License 2.0. We warmly welcome and encourage community contributions, integrations, and derivative works, subject to the following attribution requirements:

  1. Retain notices: You must retain the LICENSE and NOTICE files from the original project in any distribution.
  2. Product attribution: If you integrate AI-Infra-Guard's core code, components, or scanning engine into your open-source project, commercial product, or internal platform, you must clearly state the following in your product documentation, usage guide, or UI "About" page:

    "This project integrates AI-Infra-Guard, open-sourced by Tencent Zhuque Lab."

  3. Academic & article citation: If you use this tool in vulnerability analysis reports, security research articles, or academic papers, please explicitly mention "Tencent Zhuque Lab AI-Infra-Guard" and include a link to the repository.

Repackaging this project as an original product without disclosing its origin is strictly prohibited.

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

58 total
  1. AI-Infra-Guard v4.6.3v4.6.3Sep 24, 202615 downloads

    ## [v4.6.3] - 2026-09-24 ### Added - **DeepTeam**: Write finished test cases to disk during a run (#653) - **API Checker**: Refill failed fingerprint samples for more reliable model identification ### Fixed - **API Checker**: Support Claude 5 signatures (PR #667) - **Prompt-Eval**: Rate-limit aware backoff, circuit breaker and process-group termination - **Prompt-Eval**: Share rate-limit counter between breaker and model, harden Retry-After parsing - **Prompt-Eval**: Hoist 'import re' to module top level ### Changed - **Research (forge_bench)**: Document dataset organization and evaluation-set guidance (PR #662) - **Docs**: Add FORGE-Bench and RogueHandoff-20 to Research list (PR #661) - **Docs**: Sync FORGE-Bench and RogueHandoff-20 Research entries across 8 language READMEs - **Docs**: Add v4.6.2 What's New entry across all 9 README languages (PR #660) - **Test (agent-scan)**: Pin the detection-skill registration contract (#664) ### Contributors Elwood Zonghao Ying (NY1024), xiangfanwu, KEXNA, Devam Shah, helo060228, aigsec, aig-doc-bot

  2. AI-Infra-Guard v4.6.2v4.6.2Sep 17, 2026103 downloads

    ## [v4.6.2] - 2026-09-17 ### Added - **Research**: Add FORGE-Bench (forge_bench) — deterministic Loss-of-Control benchmark for autonomous agents - **Research**: Add clean RogueHandoff-20 benchmark under Research - **Data**: Add AIG rules [2026-09-11] - **Skill-Scan**: Bump aig-skill-scan to 0.2.2 (#656) ### Fixed - **Skill-Scan**: Reduce evidence-free false positives (PR #652) - **Skill-Scan**: Prevent model tool-call stalls and bound stalled streaming responses - **Skill-Scan**: Reconcile verdicts with public findings (PR #652) - **Extract-Vuln**: Strip CDATA wrapper and accept common tag aliases (PR #655) - **Data**: Flatten cvss map to string format to match upstream schema - **Data**: Resolve 12 YAML validation failures - **Data**: Remove redundant n8n.yaml fingerprint (upstream has n8n.io.yaml) ### Changed - **Research (forge_bench)**: Built-in OpenAI-compatible client, bilingual README, and quickstart (PR #658) - **Docs**: Document English-only contributor text and canonical input language policy - **Docs**: Add v4.6.1 What's New entry across all 9 README languages - **Docs**: Revert CATL logo acknowledgement added to all README languages (PR #654/#659) ### Contributors E

  3. AI-Infra-Guard v4.6.1v4.6.1Sep 10, 202674 downloads

    ## [v4.6.1] - 2026-09-10 ### Added - **API Checker**: Add Gemini, Gemma, and GLM fingerprints - **API Checker**: Update GLM-5.3-Flash fingerprint baseline - **API Checker**: Update baseline tests ### Fixed - **MCP-Scan**: Adapt to MCP Python SDK 2.x API changes (PR #606) - **MCP-Scan**: Cast read_timeout_seconds to float for SDK 2.x type safety - **MCP-Scan**: Mark empty scan results as possibly-incomplete (PR #623) - **MCP-Scan**: Preserve security findings in context compaction prompt - **MCP-Scan**: Always set scanNote in result_meta and log in English - **MCP-Scan**: Surface the underlying error when MCP connection fails (PR #534) - **Skill-Scan**: Stop silently hiding .pyc files and skip-dir payloads - **Task API**: Add skill_scan task type - **Parser**: Keep pre-release versions below their release in versionCheck (PR #588) - **Data**: Correct mislabeled product names for CVE-2026-13236/13237/61428 (PR #642) - **Docker**: Use Tencent Debian mirror for agent build ### Changed - **Docs**: Add CONTRIBUTING, CODE_OF_CONDUCT, issue/PR templates - **Docs**: Update skill-scan README pre_scan capability description - **Docs**: Update task API comment clarifying attachments priorit

  4. AI-Infra-Guard v4.6.0v4.6.0Aug 26, 2026141 downloads

    ## [v4.6.0] - 2026-08-26 ### Added - **API Checker**: New API security audit module with web proxy integration, unified CLI command, and detection algorithms (PR #511) - **LLM API Poisoning Detection**: New detection for LLM API poisoning attacks (PR #568) - **Agent-Scan (aig-agent-redteam)**: v5.0.0 mutation engine refactor, merge workflow-attack into mutation-attack - **YAML Validation**: Strict validation for required ID and severity fields in vulnerability rules - **Research**: DeepSeek Harness prompt injection assessment - **Data**: AIG rules [2026-08-07] and [2026-08-14] ### Fixed - **MCP**: Migrate clients to SDK 2.0; fix streamable_http_client headers param incompatibility with MCP SDK 1.28+ - **MCP-Scan**: Strip lone surrogates from non-UTF-8 filenames; use timedelta for ClientSession read_timeout_seconds - **Skill-Scan**: Strip lone surrogates to prevent JSON serialization crash - **Data**: Remove case-colliding duplicate vulnerability rules; escape credential-like reference labels - **PromptSecurity**: Add missing httpx dependency; stop double-translating case.reason; translate jailbreak report content - **Agent**: Extract pure URL from user input for MCP scan server_u

  5. AI-Infra-Guard v4.5.2v4.5.2Aug 17, 2026194 downloads

    ## [v4.5.2] - 2026-08-17 ### Added - **Research**: Add SkillJack project (536340d5, 78ae6df1) - **Data**: Add AIG rules [2026-07-31] (3d9af43d) - **Data**: Add GET-only fingerprints for Qdrant, Chroma, and Weaviate (d54543c4) ### Refactored - Refactor(skills/aig-agent-redteam): v5.0.0 mutation engine refactor + merge workflow-attack into mutation-attack (e989411f) ### Fixed - Fix(mcp-scan): Prevent RCE via prompt injection in dynamic scan mode (9ebcff15) - Fix(skill-scan): Prevent charset content smuggling (16495756) - Fix(skill-scan): Stop hiding compiled bytecode from audit surface (8d526653) - Fix: Correct streamable_http_client import name in mcp_tools.py (384c1c0e) - Fix(llm): Remove hardcoded temperature parameters (f18ae642) - Fix(data): Correct CVE-2026-61428 version rule to version < "4.6.78" (16ed3967) ### Changed - Docs: Sync component tables and agent-scan detection skills (788ae096) - Docs(skill-scan): Add text_decoder.py to project structure, update pre_scan description (17365158) - Docs: Trim What's New to latest 5 entries across all 9 README languages (cbe58e69) - Docs: Reorder Xiangfan after Fyoung and add Elwood to Core Members across 9 README languages (5c29b

Code frequency

additions and deletions
+191.7K-191.7KWeek of 2025-09-28: +9 linesWeek of 2025-09-28: -7 linesWeek of 2025-10-05: +2 linesWeek of 2025-10-05: -2 linesWeek of 2025-10-12: +478 linesWeek of 2025-10-12: -61 linesWeek of 2025-10-19: +3,831 linesWeek of 2025-10-19: -794 linesWeek of 2025-10-26: +1,391 linesWeek of 2025-10-26: -391 linesWeek of 2025-11-02: +849 linesWeek of 2025-11-02: -169 linesWeek of 2025-11-09: +114 linesWeek of 2025-11-09: -99 linesWeek of 2025-11-16: +98 linesWeek of 2025-11-16: -56 linesWeek of 2025-11-23: +4,096 linesWeek of 2025-11-23: -1 linesWeek of 2025-11-30: +191,730 linesWeek of 2025-11-30: -8,162 linesWeek of 2025-12-07: +1,414 linesWeek of 2025-12-07: -163 linesWeek of 2025-12-14: +2,291 linesWeek of 2025-12-14: -12 linesWeek of 2025-12-21: +3,345 linesWeek of 2025-12-21: -5,109 linesWeek of 2025-12-28: +22 linesWeek of 2025-12-28: -6 linesWeek of 2026-01-04: +2,414 linesWeek of 2026-01-04: -1,964 linesWeek of 2026-01-11: +24,225 linesWeek of 2026-01-11: -6,703 linesWeek of 2026-01-18: +6,071 linesWeek of 2026-01-18: -11,475 linesWeek of 2026-01-25: +2,683 linesWeek of 2026-01-25: -965 linesWeek of 2026-02-01: +1,886 linesWeek of 2026-02-01: -1,909 linesWeek of 2026-02-08: +3,497 linesWeek of 2026-02-08: -144 linesWeek of 2026-02-15: +0 linesWeek of 2026-02-15: -0 linesWeek of 2026-02-22: +2,133 linesWeek of 2026-02-22: -675 linesWeek of 2026-03-01: +201 linesWeek of 2026-03-01: -215 linesWeek of 2026-03-08: +3,701 linesWeek of 2026-03-08: -6,526 linesWeek of 2026-03-15: +12,078 linesWeek of 2026-03-15: -916 linesWeek of 2026-03-22: +39,776 linesWeek of 2026-03-22: -5,088 linesWeek of 2026-03-29: +19,615 linesWeek of 2026-03-29: -8,369 linesWeek of 2026-04-05: +6,969 linesWeek of 2026-04-05: -2,495 linesWeek of 2026-04-12: +10,571 linesWeek of 2026-04-12: -4,794 linesWeek of 2026-04-19: +9,682 linesWeek of 2026-04-19: -3,946 linesWeek of 2026-04-26: +12 linesWeek of 2026-04-26: -1 linesWeek of 2026-05-03: +13,863 linesWeek of 2026-05-03: -11,109 linesWeek of 2026-05-10: +26,752 linesWeek of 2026-05-10: -132 linesWeek of 2026-05-17: +14,952 linesWeek of 2026-05-17: -287 linesWeek of 2026-05-24: +463 linesWeek of 2026-05-24: -24 linesWeek of 2026-05-31: +723 linesWeek of 2026-05-31: -48 linesWeek of 2026-06-07: +405 linesWeek of 2026-06-07: -41 linesWeek of 2026-06-14: +31,395 linesWeek of 2026-06-14: -49 linesWeek of 2026-06-21: +735 linesWeek of 2026-06-21: -223 linesWeek of 2026-06-28: +31,841 linesWeek of 2026-06-28: -8,067 linesWeek of 2026-07-05: +1,106 linesWeek of 2026-07-05: -351 linesWeek of 2026-07-12: +17,944 linesWeek of 2026-07-12: -12,418 linesWeek of 2026-07-19: +71,911 linesWeek of 2026-07-19: -42,908 linesWeek of 2026-07-26: +3,737 linesWeek of 2026-07-26: -730 linesWeek of 2026-08-02: +20,623 linesWeek of 2026-08-02: -88 linesWeek of 2026-08-09: +17,577 linesWeek of 2026-08-09: -6,513 linesWeek of 2026-08-16: +67,222 linesWeek of 2026-08-16: -4,381 linesWeek of 2026-08-23: +518 linesWeek of 2026-08-23: -166 linesWeek of 2026-08-30: +1,191 linesWeek of 2026-08-30: -76 linesWeek of 2026-09-06: +10,411 linesWeek of 2026-09-06: -188 linesWeek of 2026-09-13: +15,733 linesWeek of 2026-09-13: -489 linesWeek of 2026-09-20: +1,267 linesWeek of 2026-09-20: -281 linesSep 28, 2025Sep 20, 2026
+705.6K lines added, -159.8K removed over the last year.

Commits per week

last 52 weeks
500Week of 2025-09-28: 4 commitsWeek of 2025-10-05: 2 commitsWeek of 2025-10-12: 2 commitsWeek of 2025-10-19: 5 commitsWeek of 2025-10-26: 13 commitsWeek of 2025-11-02: 6 commitsWeek of 2025-11-09: 7 commitsWeek of 2025-11-16: 2 commitsWeek of 2025-11-23: 3 commitsWeek of 2025-11-30: 50 commitsWeek of 2025-12-07: 13 commitsWeek of 2025-12-14: 7 commitsWeek of 2025-12-21: 32 commitsWeek of 2025-12-28: 2 commitsWeek of 2026-01-04: 31 commitsWeek of 2026-01-11: 30 commitsWeek of 2026-01-18: 26 commitsWeek of 2026-01-25: 26 commitsWeek of 2026-02-01: 32 commitsWeek of 2026-02-08: 12 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 8 commitsWeek of 2026-03-01: 3 commitsWeek of 2026-03-08: 16 commitsWeek of 2026-03-15: 19 commitsWeek of 2026-03-22: 45 commitsWeek of 2026-03-29: 18 commitsWeek of 2026-04-05: 20 commitsWeek of 2026-04-12: 42 commitsWeek of 2026-04-19: 29 commitsWeek of 2026-04-26: 1 commitsWeek of 2026-05-03: 3 commitsWeek of 2026-05-10: 38 commitsWeek of 2026-05-17: 13 commitsWeek of 2026-05-24: 4 commitsWeek of 2026-05-31: 6 commitsWeek of 2026-06-07: 11 commitsWeek of 2026-06-14: 6 commitsWeek of 2026-06-21: 26 commitsWeek of 2026-06-28: 36 commitsWeek of 2026-07-05: 9 commitsWeek of 2026-07-12: 17 commitsWeek of 2026-07-19: 18 commitsWeek of 2026-07-26: 15 commitsWeek of 2026-08-02: 8 commitsWeek of 2026-08-09: 7 commitsWeek of 2026-08-16: 37 commitsWeek of 2026-08-23: 19 commitsWeek of 2026-08-30: 11 commitsWeek of 2026-09-06: 12 commitsWeek of 2026-09-13: 18 commitsWeek of 2026-09-20: 6 commitsSep 28, 2025Sep 20, 2026
826 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 1 commitsSun 1:00 — 0 commitsSun 2:00 — 1 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 0 commitsSun 7:00 — 1 commitsSun 8:00 — 0 commitsSun 9:00 — 0 commitsSun 10:00 — 4 commitsSun 11:00 — 0 commitsSun 12:00 — 6 commitsSun 13:00 — 1 commitsSun 14:00 — 1 commitsSun 15:00 — 4 commitsSun 16:00 — 4 commitsSun 17:00 — 2 commitsSun 18:00 — 0 commitsSun 19:00 — 3 commitsSun 20:00 — 7 commitsSun 21:00 — 0 commitsSun 22:00 — 0 commitsSun 23:00 — 0 commitsMon 0:00 — 0 commitsMon 1:00 — 0 commitsMon 2:00 — 0 commitsMon 3:00 — 0 commitsMon 4:00 — 0 commitsMon 5:00 — 0 commitsMon 6:00 — 0 commitsMon 7:00 — 0 commitsMon 8:00 — 0 commitsMon 9:00 — 14 commitsMon 10:00 — 25 commitsMon 11:00 — 32 commitsMon 12:00 — 2 commitsMon 13:00 — 2 commitsMon 14:00 — 22 commitsMon 15:00 — 23 commitsMon 16:00 — 14 commitsMon 17:00 — 16 commitsMon 18:00 — 14 commitsMon 19:00 — 30 commitsMon 20:00 — 18 commitsMon 21:00 — 1 commitsMon 22:00 — 0 commitsMon 23:00 — 0 commitsTue 0:00 — 3 commitsTue 1:00 — 0 commitsTue 2:00 — 0 commitsTue 3:00 — 0 commitsTue 4:00 — 1 commitsTue 5:00 — 0 commitsTue 6:00 — 0 commitsTue 7:00 — 0 commitsTue 8:00 — 1 commitsTue 9:00 — 4 commitsTue 10:00 — 37 commitsTue 11:00 — 36 commitsTue 12:00 — 2 commitsTue 13:00 — 6 commitsTue 14:00 — 40 commitsTue 15:00 — 39 commitsTue 16:00 — 29 commitsTue 17:00 — 31 commitsTue 18:00 — 24 commitsTue 19:00 — 22 commitsTue 20:00 — 17 commitsTue 21:00 — 7 commitsTue 22:00 — 11 commitsTue 23:00 — 1 commitsWed 0:00 — 0 commitsWed 1:00 — 6 commitsWed 2:00 — 0 commitsWed 3:00 — 0 commitsWed 4:00 — 0 commitsWed 5:00 — 0 commitsWed 6:00 — 0 commitsWed 7:00 — 7 commitsWed 8:00 — 5 commitsWed 9:00 — 14 commitsWed 10:00 — 36 commitsWed 11:00 — 35 commitsWed 12:00 — 2 commitsWed 13:00 — 3 commitsWed 14:00 — 24 commitsWed 15:00 — 58 commitsWed 16:00 — 42 commitsWed 17:00 — 45 commitsWed 18:00 — 28 commitsWed 19:00 — 24 commitsWed 20:00 — 5 commitsWed 21:00 — 5 commitsWed 22:00 — 3 commitsWed 23:00 — 4 commitsThu 0:00 — 1 commitsThu 1:00 — 2 commitsThu 2:00 — 0 commitsThu 3:00 — 1 commitsThu 4:00 — 0 commitsThu 5:00 — 0 commitsThu 6:00 — 0 commitsThu 7:00 — 0 commitsThu 8:00 — 0 commitsThu 9:00 — 12 commitsThu 10:00 — 51 commitsThu 11:00 — 36 commitsThu 12:00 — 28 commitsThu 13:00 — 5 commitsThu 14:00 — 28 commitsThu 15:00 — 75 commitsThu 16:00 — 42 commitsThu 17:00 — 37 commitsThu 18:00 — 14 commitsThu 19:00 — 32 commitsThu 20:00 — 15 commitsThu 21:00 — 7 commitsThu 22:00 — 0 commitsThu 23:00 — 0 commitsFri 0:00 — 1 commitsFri 1:00 — 2 commitsFri 2:00 — 0 commitsFri 3:00 — 2 commitsFri 4:00 — 0 commitsFri 5:00 — 1 commitsFri 6:00 — 0 commitsFri 7:00 — 0 commitsFri 8:00 — 1 commitsFri 9:00 — 2 commitsFri 10:00 — 42 commitsFri 11:00 — 28 commitsFri 12:00 — 3 commitsFri 13:00 — 7 commitsFri 14:00 — 23 commitsFri 15:00 — 43 commitsFri 16:00 — 52 commitsFri 17:00 — 20 commitsFri 18:00 — 8 commitsFri 19:00 — 14 commitsFri 20:00 — 5 commitsFri 21:00 — 2 commitsFri 22:00 — 1 commitsFri 23:00 — 3 commitsSat 0:00 — 3 commitsSat 1:00 — 1 commitsSat 2:00 — 5 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 0 commitsSat 7:00 — 0 commitsSat 8:00 — 0 commitsSat 9:00 — 0 commitsSat 10:00 — 0 commitsSat 11:00 — 1 commitsSat 12:00 — 0 commitsSat 13:00 — 1 commitsSat 14:00 — 0 commitsSat 15:00 — 0 commitsSat 16:00 — 0 commitsSat 17:00 — 1 commitsSat 18:00 — 0 commitsSat 19:00 — 1 commitsSat 20:00 — 0 commitsSat 21:00 — 1 commitsSat 22:00 — 0 commitsSat 23:00 — 2 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Aug 27, 2026weekly#12+1,247
Aug 26, 2026weekly#12+1,247
Aug 25, 2026weekly#13+1,212
Aug 24, 2026daily#13+150
Aug 23, 2026daily#13+150
Aug 22, 2026daily#11+50
Aug 21, 2026daily#11+50