In this news:
China’s cybersecurity watchdog has warned against third-party AI “skills” packages that claim to bypass model safety guard rails and generate otherwise prohibited content, or provide access to cryptocurrency-mining functions, saying the tools expose users to data leaks and money-laundering risks.
The National Computer Network Emergency Response Coordination Centre (CNCERT) issued the warning on Tuesday via its official WeChat account, highlighting the rapid emergence of a grey market for unregulated AI extensions.
In the AI ecosystem, skills function as plug-ins or specialised code packages that expand the capabilities of AI agents and models. Similar to smartphone apps, they can connect AI systems to external databases, automate workflows and integrate with third-party software or online services, enabling more complex tasks beyond text generation.
However, CNCERT said some skills are marketed as tools for circumventing built-in restrictions in AI models, allowing users to generate prohibited content or access cryptocurrency-mining functions, which remain banned in mainland China.
The agency warned that using such tools could result in privacy breaches, account suspensions and potential legal consequences.
While the AI skills ecosystem includes many legitimate offerings, CNCERT said users should obtain skills only through official channels, follow the principle of least privilege when granting permissions and promptly revoke unnecessary access to sensitive data.
The watchdog also pointed to a growing number of malicious skills designed to trick AI agents into downloading mining software or persuade users to run it themselves to generate “privacy-focused” tokens.
Because cryptocurrency mining consumes large amounts of computing power, it can increase electricity costs, reduce device performance and accelerate hardware deterioration.
The warning comes as China’s AI agent ecosystem expands rapidly. Platforms including Manus, Coze, Dify and Flowith have encouraged third-party developers to create specialised skills that extend the functionality of their models.
That trend has fuelled concerns over how much control platform operators retain over code executed by external components. Security researchers have warned that AI agents capable of downloading and running third-party code introduce new attack surfaces that hackers can exploit.
According to JailbreakBench, an open-source AI security testing platform, malicious prompt injections and compromised skills continue to achieve high success rates in bypassing safety controls, including those deployed by leading AI developers such as OpenAI and Anthropic.
To reduce these risks, CNCERT urged enterprises to establish strict whitelists for approved AI skills and conduct comprehensive security reviews before deploying third-party components.
The agency also recommended running AI agents in isolated environments, classifying them according to data sensitivity, and implementing robust data-masking and temporary authorisation mechanisms.