China's CNCERT flags rogue AI skill packages for crypto mining, guardrail bypass
Synopsis
Key Takeaways
China's top cybersecurity authority has issued a formal warning against unauthorised third-party AI 'skills' packages being marketed to bypass model safety guardrails and enable cryptocurrency mining — activities that remain banned on the Chinese mainland. The National Computer Network Emergency Response Coordination Centre (CNCERT) published the alert on Tuesday, 10 June 2026, via its official WeChat account, flagging a rapidly expanding grey market for unregulated AI extensions.
What Are AI Skills and Why Do They Matter
In the AI ecosystem, skills function as plug-ins or specialised code packages that extend the capabilities of AI agents and models. Much like smartphone apps, they can connect AI systems to external databases, automate workflows and integrate with third-party software or online services, enabling tasks well beyond standard text generation.
The category has grown swiftly alongside the proliferation of large language models and autonomous AI agents, creating a parallel distribution layer that regulators are only beginning to scrutinise.
The Threat Landscape CNCERT Identified
CNCERT said some skills packages are being marketed explicitly as tools for circumventing built-in restrictions in AI models, allowing users to generate otherwise prohibited content. Others reportedly provide access to cryptocurrency-mining functions — a category of activity that has been prohibited in mainland China since 2021.
The agency warned that deploying such tools could expose users to privacy breaches, account suspensions, data leaks, money-laundering risks and potential legal consequences under existing Chinese law.
Why It Matters
The alert signals that China's regulatory apparatus is extending its oversight from foundational AI models — already subject to the country's Generative AI Interim Measures — down to the application and extension layer. This mirrors global concerns about agentic AI systems that can autonomously interact with external services, raising accountability gaps that existing frameworks were not designed to address.
The warning also arrives as domestic AI adoption accelerates, with enterprises and individual developers increasingly building on top of models from companies such as Baidu, Alibaba and DeepSeek, creating fertile ground for third-party extension marketplaces.
CNCERT's Recommended Safeguards
CNCERT advised users to obtain AI skills exclusively through official, verified channels and to apply the principle of least privilege when granting permissions to any extension. Users should also promptly revoke unnecessary access to sensitive data once a task is complete, the agency said.
The guidance draws a clear line between the legitimate AI skills ecosystem — which the agency acknowledged includes many compliant offerings — and the grey-market tools it is targeting.
What's Next
With CNCERT's warning now public, platform operators and app stores hosting AI skill repositories face implicit pressure to tighten vetting procedures. Analysts expect follow-on enforcement guidance from the Cyberspace Administration of China (CAC) as the country moves to close regulatory gaps in the agentic AI stack before they become systemic vulnerabilities.