Tencent Zhuque Lab
Tencent Zhuque Lab is an elite security research laboratory established in 2019 under Tencent's Security Platform Department. It focuses on practical offensive and defensive research in AI security, including LLM security, AI-agent security, AI-empowered security, and AI-generated-content detection, and develops tools and benchmarks to help developers and security teams assess and mitigate AI risks.
At a Glance
- Enterprise security teams
- AI developers and application teams
- LLM and AI-infrastructure operators
- AI-agent and MCP developers
- +2 more
AI Tools by Tencent Zhuque Lab
(4)WeKnora
Open Source Enterprise RAG Platform
BrowserSkill
AI Agent Browser Automation Bridge
TeamAI CLI
AI Config Sync CLI for Teams
AI-Infra-Guard (A.I.G)
AI Security Testing Platform
Discussions
No discussions yet
Be the first to start a discussion about Tencent Zhuque Lab
Latest News
A.I.G Red Team's DeepSeek Harness test ran 14,560 evaluations and reported prompt-injection risks spanning attack expressions, files, and skills.
Zhuque Lab reported SCTPhantom, an 18-year-old Linux SCTP ASCONF use-after-free tracked as CVE-2026-64564.
The lab published an analysis of the AI-agent Memory Heist attack chain and demonstrated detection with A.I.G's agent-scan module.
A.I.G Agent Security Drill SKILL was open-sourced for lightweight local AI-agent security testing.
Products & Services
An open-source, full-stack AI red-teaming and security-testing platform. It combines jailbreak evaluation, AI-infrastructure vulnerability scanning, MCP-server and agent-skill scanning, agent/workflow scanning, OpenClaw security scanning, and model/API relay checking; it provides a web interface, APIs, Docker deployment, and CLI components.
An AI-generated-content detection product using deep learning to identify AI-generated text, images, and other content so users can distinguish AIGC material.
A systematic AI-security threat framework mapping threats and attack paths across AI infrastructure and model/application layers, with structured defensive guidance. The published matrix covers 38 threats across four risk domains.
A cybersecurity-LLM evaluation platform and benchmark jointly built by Tencent Zhuque Lab, Tencent Security's Xuanwu/Keen Lab, university research groups, and Shanghai AI Laboratory's OpenCompass team. It evaluates large models on security knowledge, reasoning, and multiple security domains and languages.
Market Position
Zhuque Lab positions A.I.G as a comprehensive, open-source, AI-focused red-teaming platform that combines model evaluation, infrastructure vulnerability scanning, MCP and agent-skill analysis, and agent-workflow testing. In the SkillTrustBench comparison set, relevant alternative scanners include Cisco Skill Scanner, NVIDIA SkillSpector, and Skill Vetter; A.I.G differentiates through its broader full-stack scope, multi-component CVE coverage, CLI/API/web deployment options, and integration of scanners with benchmark and threat-research work.
Leadership
Founders
Yong Yang
Head of Tencent Security Platform Department; long-time security leader at Tencent.
Zheng Xing
Director of Tencent Zhuque Lab; previously held senior security research roles within Tencent.
Executive Team
Yong Yang
Head of Tencent Security Platform Department
The A.I.G project credits Yang with initiating A.I.G and proposing automated assessment of AI-agent loss-of-control risks, guiding expansion from AI-infrastructure vulnerability scanning to agent execution risk, tool misuse, and permission-boundary evaluation.
Xing Zheng
Head of Tencent Zhuque Lab
The A.I.G project credits Zheng with proposing an automated vulnerability-update and benchmark-alignment mechanism for continuously updating AI-infrastructure fingerprints, CVE/GHSA rules, and benchmarks.
Board of Directors
Founding Story
Tencent says the lab was established in 2019 within the Security Platform Department to pursue practical offense-and-defense work and frontier research as AI systems became a security concern. Its initial and continuing vision is to safeguard intelligent systems through research, vulnerability discovery, responsible disclosure, open-source tooling, and structured benchmarks.
Business Model
Revenue Model
The lab's publicly described offerings are primarily research, open-source tools, benchmarks, and free self-assessment software rather than a disclosed commercial subscription business. A.I.G is free and open source under Apache 2.0; the repository also points to an invitation-code Pro version at aigsec.ai.
Pricing Tiers
Apache 2.0 licensed; deployable with Docker or from source and usable through web UI, APIs, and CLI tools.
The repository describes an online Pro version with advanced features and improved performance at aigsec.ai; public price was not shown.
Target Markets
- Enterprise security teams
- AI developers and application teams
- LLM and AI-infrastructure operators
- AI-agent and MCP developers
- Open-source maintainers and platform communities
- Cybersecurity researchers and academic benchmark users
- Pre-deployment security testing and red teaming of LLM applications and AI agents
- Security assessment of MCP servers, agent skills, plugins, and AI supply chains
- Vulnerability scanning of deployed AI infrastructure and frameworks
- Jailbreak and loss-of-control evaluation of large language models
- Security testing integrated into enterprise CI/CD pipelines
- OpenClaw and agent-environment security self-assessment
- NVIDIA
- Microsoft
- OpenClaw