China sounds alarm over AI ‘skills’ that evade guard rails and mine crypto
China's cybersecurity watchdog, CNCERT, has issued a warning against third-party AI 'skills' that bypass safety measures to generate prohibited content and facilitate cryptocurrency mining, exposing users to data leaks and legal risks.
Intelligence analysis by Gemini 2.5 Flash

A Chinese cybersecurity agency warns about a growing grey market for unregulated AI 'skills' or plug-ins. These tools are being used to circumvent AI model restrictions, allowing for the generation of illicit content and access to cryptocurrency-mining functions, which are banned in mainland China, posing significant security and legal dangers to users.
Imagine your smart robot friend can learn new tricks, like how to draw or tell stories. But some people are making secret tricks that make the robot do naughty things, like drawing stuff it's not supposed to or finding hidden digital coins that are against the rules in China. China's internet police are saying, 'Watch out! These secret tricks can steal your private info or get you into trouble!' So, it's like only getting apps for your phone from the official store, not from a shady secret shop, so you stay safe.
Analysis
China's National Computer Network Emergency Response Coordination Centre (CNCERT) has raised concerns over the proliferation of unregulated third-party AI "skills" packages. These "skills" are essentially plug-ins or specialized code that extend the functionalities of AI models, similar to smartphone applications. They can enable AI systems to interact with external databases, automate tasks, and integrate with other software.
Malicious Use Cases
CNCERT specifically warned that some of these skills are being marketed with the explicit purpose of bypassing the built-in safety mechanisms of AI models. This circumvention allows users to generate content that would otherwise be prohibited or to access cryptocurrency-mining capabilities. Cryptocurrency activities, including mining, are banned in mainland China, making these tools a vector for illegal operations.
Risks to Users
The cybersecurity watchdog emphasized that using such tools carries substantial risks. These include privacy breaches, where sensitive user data could be exposed, and account suspensions on platforms. More gravely, users could face potential legal consequences for engaging in activities facilitated by these malicious AI skills, such as money laundering.
Recommendations for Safety
While acknowledging the existence of many legitimate AI skills within the ecosystem, CNCERT advised users to exercise caution. The agency recommends obtaining AI skills exclusively through official and verified channels. Furthermore, users should adhere to the principle of "least privilege" when granting permissions to these skills, ensuring they only have access to the absolute minimum data required for their function. It is also crucial, according to CNCERT, to promptly revoke any unnecessary access permissions to sensitive data.
Key points
- China's CNCERT warns against third-party AI 'skills' that bypass safety guard rails.
- These malicious skills enable generation of prohibited content and access to banned cryptocurrency-mining functions.
- Users face risks of privacy breaches, account suspensions, and legal consequences.
- The agency advises obtaining AI skills only through official channels and applying the principle of least privilege for permissions.
- A grey market for unregulated AI extensions is rapidly emerging in the AI ecosystem.
Despite the warnings, the development of AI 'skills' in a regulated and secure manner could significantly enhance the capabilities of AI agents and models, enabling them to perform more complex tasks and integrate seamlessly with various services. This expansion could lead to innovative applications and increased efficiency across many industries, provided users and developers adhere to best practices and official channels.
The proliferation of unregulated AI 'skills' poses a significant threat, potentially leading to widespread data breaches, financial crimes like money laundering through crypto-mining, and a breakdown of AI model safety guard rails. This could erode public trust in AI, necessitate stricter government oversight, and lead to severe legal repercussions for individuals and organizations involved.



