Repository
Tencent/AI-Infra-Guard agent skills
- skills
- 13
- GitHub stars
- 6.8k
GitHub description: “A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.”
- Stars
- 6,766 (636 forks)
- Licence
- Apache-2.0
- Last push
- Oct 2026
- Created
- Dec 2024
- Homepage
- tencent.github.io/AI-Infra-Guard
- agent
- llm
- scanner
- security
- vulnerability
- agent-security
- ai-red-teaming
- ai-security
- llm-jailbreak
- llm-security
- ai-infra
- mcp-scan
- skill-scanner
- llm-evaluation
- openclaw-security
- prompt-security
Install all skills
npx skills add Tencent/AI-Infra-GuardAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in Tencent/AI-Infra-Guard, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries. | Tencent/ | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | today |
| 2 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | today |
| 3 | Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths. | Tencent/ | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction. | Tencent/ | 6.8k | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | today |
| 5 | Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks. | Tencent/ | 6.8k | — | ~9.5k | Automated safety check: Pass | MIT | today |
| 6 | Probes an AI agent for supply-chain weaknesses: whether it loads untrusted plugins, tools or models, updates dependencies without pinning, or trusts user-supplied artifacts. | Tencent/ | 6.8k | — | ~760 | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Detect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows. | Tencent/ | 6.8k | — | ~593 | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Tests a target AI agent for sensitive information disclosure, such as its system prompt, credentials, personal data and internal configuration, using escalating dialogue probes. | Tencent/ | 6.8k | — | ~954 | Automated safety check: Pass | Apache-2.0 | today |
| 9 | Detect unsafe file handling and path traversal in upload/save/extract flows. | Tencent/ | 6.8k | — | ~789 | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Detect hardcoded secrets in code or configuration accessible to the target agent. | Tencent/ | 6.8k | — | ~849 | Automated safety check: Notes | Apache-2.0 | today |
| 11 | Detect data leakage, missing boundaries, or privilege mismatch in inter-agent communication. | Tencent/ | 6.8k | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 12 | Detect persistent instruction injection or long-term memory poisoning. | Tencent/ | 6.8k | — | ~791 | Automated safety check: Pass | Apache-2.0 | today |
| 13 | Detect direct prompt injection or instruction override via user message (no external content). | Tencent/ | 6.8k | — | ~629 | Automated safety check: Warn | Apache-2.0 | today |
Questions, answered from the data.
What is the best skill in Tencent/AI-Infra-Guard?
Authorization Bypass Detection from Tencent/AI-Infra-Guard ranks first of the 13 skills in Tencent/AI-Infra-Guard listed here, with the highest score: its repository has 6.8k GitHub stars, its SKILL.md loads about 753 tokens and it passes the automated safety check with no findings. Next come Agent Tool Abuse Detection and Web Exfiltration Detection.
Are the skills in Tencent/AI-Infra-Guard official?
None yet. All 13 skills in Tencent/AI-Infra-Guard listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How do I install all skills from Tencent/AI-Infra-Guard?
Run npx skills add Tencent/AI-Infra-Guard in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.