Skip to content

Releases: Tencent/AI-Infra-Guard

AI-Infra-Guard v4.5.2

Choose a tag to compare

@github-actions github-actions released this 17 Aug 02:30

[v4.5.2] - 2026-08-17

Added

  • Research: Add SkillJack project (536340d, 78ae6df)
  • Data: Add AIG rules [2026-07-31] (3d9af43)
  • Data: Add GET-only fingerprints for Qdrant, Chroma, and Weaviate (d54543c)

Refactored

  • Refactor(skills/aig-agent-redteam): v5.0.0 mutation engine refactor + merge workflow-attack into mutation-attack (e989411)

Fixed

  • Fix(mcp-scan): Prevent RCE via prompt injection in dynamic scan mode (9ebcff1)
  • Fix(skill-scan): Prevent charset content smuggling (1649575)
  • Fix(skill-scan): Stop hiding compiled bytecode from audit surface (8d52665)
  • Fix: Correct streamable_http_client import name in mcp_tools.py (384c1c0)
  • Fix(llm): Remove hardcoded temperature parameters (f18ae64)
  • Fix(data): Correct CVE-2026-61428 version rule to version < "4.6.78" (16ed396)

Changed

  • Docs: Sync component tables and agent-scan detection skills (788ae09)
  • Docs(skill-scan): Add text_decoder.py to project structure, update pre_scan description (1736515)
  • Docs: Trim What's New to latest 5 entries across all 9 README languages (cbe58e6)
  • Docs: Reorder Xiangfan after Fyoung and add Elwood to Core Members across 9 README languages (5c29b24)
  • Docs: Fix v4.5.0 release date from 2026-07-24 to 2026-07-27 across 9 README languages (a41187e)
  • Docs: Rename PromptSecurity to Jailbreak Evaluation in v4.5.1 What's New; remove bug fix entries (240bc3a)
  • Docs: Add v4.5.1 What's New entry across 9 README languages; update agent-scan skill list (ca2c2f2)
  • Chore(skills): Remove outdated v5.0.0 changelog from aig-agent-redteam SKILL.md (1c14dcd)

Contributors

Special thanks to @Elwood Ying, @xiangfanwu, @zhuque, @hiddingtrojans, @NY1024, @kexinoh, @feiyang666, @AIG-Bot, @aig-doc-bot


AI-Infra-Guard v4.5.1

Choose a tag to compare

@github-actions github-actions released this 30 Jul 07:48

[v4.5.1] - 2026-07-30

Added

  • PromptSecurity: Add Many-Shot, PAIR, GOAT and ActorAttack multi-turn jailbreak attacks (a420945)
  • Agent-Scan: Add 5 new OWASP detection skills (agentic-supply-chain, cascading-failure, human-agent-trust, inter-agent-comm, unexpected-code-execution) (96d9132, 11f4854)
  • Agent-Scan: Add web-exfiltration-detection skill and case2 test (39cddc0)
  • MCP-Scan: Add 4 new MCP security detection rules (hardcoded secrets, insecure deserialization) (8db11c7)
  • Data: Add AIG rules [2026-07-24] (b80c628)
  • Docs: Add v4.5.0 What's New entry across all 9 README languages (014103f)

Fixed

  • Fix(frontend): Prevent checkbox jumping when attack method text is long (1569b30) — Closes #331
  • Fix: Remove duplicate fingerprint open-webui.yaml (7cb4805)
  • Fix: Convert cvss dict to string, remove reference from info block (8fe2935)
  • Fix: Unify author to A.I.G bot (bb51fe5)

Changed

  • Docs: Update v4.5.0 What's New with 5-item summary and revise bottom links across all 9 README languages (3121864)
  • Docs: Replace broken star-history link with sealed_token embed, remove AIG_Technical_Report.pdf (8b3f3d9)

AI-Infra-Guard v4.5.0

Choose a tag to compare

@github-actions github-actions released this 27 Jul 07:21

[v4.5.0] - 2026-07-27

Added

  • Frontend: Open-source frontend code with open-source environment configuration (5cb33e2, bed369b)
  • Agent-Scan: Modularize as standalone CLI with AIG integration support (2a18b88)
  • Agent-Scan: Add 4 new detection skills for AI agent security (5f7022f)
  • Agent-Scan: Register 4 new detection skills in _DETECTION_SKILLS (9c2c0f8)
  • MCP-Scan: Modularize with dual-mode support (CLI + AIG Web) (272c56e)
  • MCP-Scan: Add standalone mcp-scan-lite module (d93e69a)
  • MCP-Scan: Add 2 MCP security detection rules (#458)
  • MCP-Scan: Add ATR-derived MCP detection rules for further attack surfaces (#469)
  • Skill-Scan: Add Agent Skill security auditing support (78ddc07)
  • Skill-Scan: Repackage as standalone PyPI package aig-skill-scan (545ed4b)
  • Skill-Scan: SARIF 2.1.0 output + single-stage optimization (d32a56f)
  • Eval: Add agentic-tool-misuse evaluation dataset (#427)
  • Data: Add AIG rules [2026-06-29], [2026-07-13], [2026-07-17]
  • Data: Add CVE rules for Jan, Open WebUI, crewai, lobehub components
  • Data: Add ai component fingerprints (#459)
  • Data: Add missing English vuln rules
  • Docs: Add aig-skill-scan and SkillTrustBench to README
  • Docs: Add Tiane and Binus University to user acknowledgements

Changed

  • Frontend: Add open-source environment configuration and UI improvements
  • MCP-Scan: Remove redundant aig-mcp-scan-lite module (ff4a6b3)
  • Skill-Scan: Simplify to single default LLM, rebrand to aig-skill-scan (982d938)
  • Skill-Scan: Stage 2 Code Audit output Markdown report instead of XML (04f48f3)
  • Docs: Update CVE count to 1700+ and fix component counts in ai-infra-scan docs
  • Docs: Update component/vuln counts after multiple rules updates
  • Docs: Sync new "Securing the AI Agent" paper across all README languages
  • Docs: Update readme and technical_report
  • Docs: Collapse older What's New entries, keep latest 5 visible
  • Docs: Fix CVE count 1600+ -> 1900+ in README_DE and README_RU

Fixed

  • Version: Bypass GitHub API rate limit via releases/latest redirect (7a08609)
  • Task Manager: Classify Skill-Scan and rename MCP label (7be6e7c)
  • i18n: Bilingual stage titles for mcp-scan and skill-scan (0823a53, c8969cc)
  • Data: Remove duplicate OpenClaw/ directories (EN+CN) (a7d5388)
  • Data: Remove 4 CVE rules without matching fingerprints (d89e887)
  • Data: Resolve YAML parse errors in 4 vuln rule files (a7af757)
  • Data: Correct info.name to match fingerprint names (case-sensitive) (f7de1bc, 9552ebf)
  • Data: Fix missing CN translations for multiple CVE rules
  • Docs: Fix Python version requirement in skill-scan docs (3.12 -> 3.9) (fff4bb9)
  • Docs: Fix EN README CHANGELOG link text from Chinese to English (e21733d)

Chore

  • Remove redundant aig-mcp-scan-lite module
  • Add yamlcheck to .gitignore
  • Bump skill-scan version to 0.2.0

Contributors

Special thanks to @zhuque, @aigsec, @aigdocs[bot], @boyhack, @Elwood Ying, @DevamShah, @adam Lin, @AIG-Bot


AI-Infra-Guard v4.1.15

Choose a tag to compare

@github-actions github-actions released this 25 Jun 04:02

[v4.1.15] - 2026-06-25

Added

  • API: Allow omitting model token in mcp_scan and ai_infra_scan, fall back to system default model (f97d707)
  • Data: Add 6 llama.cpp CVE rules to the llama-cpp pack (8e0d417)
  • MCP: Add 3 MCP threat detection rules: tool poisoning, credential exfiltration, command injection (de57b10)

Changed

  • Docs: Add user feedback survey section to all README files (bf5ed72)
  • Docs: Fix vuln total count 1300+ -> 1600+ in ai-infra-scan docs (98d4cd9)
  • Docs: Update llama-cpp vuln count 3->9 and severity Low->Medium-High (e7b97bd)
  • Docs: Add 9 new single-turn attack operators to AIG-PromptSecurity README (9d6a589)
  • Docs: Update openclaw vuln count 628 -> 655 in ai-infra-scan docs (aba3988)
  • Docs: Fix zh v4.1.14 wording: single-turn jailbreak operators -> attack methods (e3cf9a6)
  • Docs: Remove v4.1.11 What's New entry from all 9 README languages (ec3557d)
  • Docs: Add v4.1.14 What's New and restore v4.1.11 entry across all 9 README languages (2c662d0)

Contributors

Special thanks to @zhuque, @aigsec, @aigdocs[bot], @boyhack, @DevamShah, @aig-doc-bot, @nicky, @adam Lin


AI-Infra-Guard v4.1.14

Choose a tag to compare

@github-actions github-actions released this 18 Jun 04:02

[v4.1.14] - 2026-06-18

Added

  • Skills: Add aig-agent-redteam skill for comprehensive Agent security assessment (5eb87a6)
  • Prompt Security: Add 9 single-turn jailbreak attack methods: PrefillAttack, ICA, PastTense, Overload, Jailbroken, FlipAttack, DeepInception, CodeChameleon, JAM (d48e508)
  • Eval: Add jailbreak evaluation datasets: AdvBench, CNSafe, SafeBench (e0ce12e)

Changed

  • Dispatch: Implement round-robin agent selection for load balancing (Closes #407) (cb0fa37)
  • Docs: Add AdvBench, CNSafe, SafeBench to dataset credits in prompt-eval docs (52b9737)
  • Docs: Update DeepTeam repo URL to confident-ai/deepteam (8743b1f)
  • Docs: Add Nanyang Technological University logo to README (b800978)
  • Docs: Update What's New to v4.1.13 across all README languages (bb73db9)

Contributors

Special thanks to @boyhack, @Elwood-Zonghao-Ying, @aigsec, @aigdocs[bot], @aig-doc-bot


AI-Infra-Guard v4.1.13

Choose a tag to compare

@github-actions github-actions released this 11 Jun 04:02

[v4.1.13] - 2026-06-11

Added

  • API: Add version check endpoint (Closes #376) (5ab5c0f)

Fixed

  • Scoring: Replace weighted ratio with absolute deduction model (Closes #403) (cf2170f)

Changed

  • Docs: Add China Merchants Bank logo to user appreciation section in all READMEs (c95f052)
  • Docs: Update What's New to v4.1.12 across all README languages (0a8da63)
  • Docs: Restore v4.1.11 entry in What's New across all 9 README languages (b341578)

Contributors

Special thanks to @boyhack, @zhuque, @aigsec, @aigdocs[bot]


AI-Infra-Guard v4.1.12

Choose a tag to compare

@github-actions github-actions released this 08 Jun 02:42

[v4.1.12] - 2026-06-08

Added

  • Fingerprints: Add 39 new AI web fingerprints and enhance 18 existing ones (7c438fa)

Fixed

  • Fingerprints: Fix YAML matcher syntax for CI validation (49e2552)

Changed

  • Docs: Update component count to 100+ and CVE count to 1600+ across all languages (58d97ff)
  • Docs: Add v4.1.11 to What's New across all 9 README languages (39a0cec)

Contributors

Special thanks to @zhuque, @boyhack, @aig-doc-bot


AI-Infra-Guard v4.1.11

Choose a tag to compare

@github-actions github-actions released this 17 Aug 02:30

[v4.1.11] - 2026-06-04

Changed

  • Docs: Add Wuhan University and Unicom Digital Tech logos to all READMEs (3af7f63)
  • Docs: Add v4.1.10 to What's New across all 9 README languages (5e0a6f4)

Contributors

Special thanks to @aigsec, @jucie-pie, @aig-doc-bot


AI-Infra-Guard v4.1.10

Choose a tag to compare

@github-actions github-actions released this 28 May 04:04

[v4.1.10] - 2026-05-28

Added

  • Data: Add CVE rules and fingerprints for new targets (junoclaw, lollms, sglang) (6054e45)
  • Scan: Support WebSocket agent providers (2c845e8)

Fixed

  • Scan: Resolve uv run failures in Docker and improve dify version detection (23f098a)
  • Chromium: Add defer Close() to prevent zombie processes (b617bf7)
  • Data: Correct sglang fingerprint YAML structure (version as top-level key) (653cc9a)

Changed

  • Docs: Add v4.1.9 to What's New across all 9 README languages (187442d)

Contributors

Special thanks to @feiyang666, @boyhack, @zhuque, @jucie-pie, @rocie799, @AIG-Bot, @aig-doc-bot


AI-Infra-Guard v4.1.9

Choose a tag to compare

@github-actions github-actions released this 21 May 04:04

[v4.1.9] - 2026-05-21

Added

  • Prompt Security: Add 20+ single-turn attack operators (invisible-text, case-formatting, script-system, unicode-style, classical-cipher, classic-encoding, SystemOverride, SuperUser, LinguisticConfusion, Roleplay, PromptProbing, PromptInjection, PROMISQROUTE, PermissionEscalation, Multilingual, MathProblem, InputBypass, ICRTJailbreak, GrayBox, GoalRedirection, EquaCode, ContextPoisoning) (fbac88b..14a3d01)
  • Prompt Security: Add 6 multi-turn attack operators (TreeJailbreaking, SequentialJailbreak, LinearJailbreaking, CrescendoJailbreaking, BestofN, BadLikertJudge) (f4e7cd8..6116a8a)
  • Prompt Security: Register and document newly added attack operators (03d67de, ce3869c)
  • Scan: Add indirect prompt injection defense to scanning agent prompts (bce80c9)

Changed

  • Docs: Reorder academic citation papers by publication date descending (0ae8625)
  • Docs: Normalize quotes in DE/RU paper citations to standard format (b9b4d2b)
  • Docs: Simplify overly formal acknowledgement wording across all languages (5926ade)
  • Docs: Add Changan Auto and HUST logos to user appreciation section (968710f)
  • Docs: Sync HUST and Nankai University logo heights (45px) across all READMEs (7ef9cd4, c59eb29)
  • Docs: Add 1 new related paper to README (b93e1e0)

Contributors

Special thanks to @y3oZ, @truman, @zhuque, @boyhack, @aigsec, @aig-doc-bot, @jucie-pie