China’s national cyber agency warned that third-party AI “skills” are being sold to bypass model guard rails, run hidden crypto-mining, and expose user data.
CNCERT issued a public warning about a fast-growing grey market for unregulated AI extensions. In the AI ecosystem, skills act as plug-ins or specialized code packages that expand what agents and models can do, connecting them to external databases, automating workflows, and integrating third-party software much the way phone apps extend a handset. The agency said some skills are marketed specifically to circumvent built-in safety restrictions so a model produces otherwise prohibited content, and some carry cryptocurrency-mining functions that remain banned on the mainland. Using them, CNCERT cautioned, can lead to privacy breaches, account suspension, money-laundering exposure, and legal consequences. It advised obtaining skills only through official channels, granting the least privilege necessary, and promptly revoking access to sensitive data. The warning marks the point where the extension layer that sits between a model and a person became a named security risk, not a theoretical one.
model guard rails
inside extensions
risk flagged
A model can ship with working safety controls and still be steered past them by an installed extension. The risk surface here is the third-party skill layer that sits between the model and the person, where a plug-in can quietly defeat the guard rails the model was released with. AVAAS evaluates how an AI system behaves at the point its output reaches a person, including agentic systems that load external skills and call tools, so a deployment that can be walked past its own safety controls by an added extension does not earn a passing grade. AVAAS for agentic systems extends the same standard to agents that install third-party skills, giving the deployer documented, third-party evidence that the assembled system behaves as claimed, not just the base model in isolation.
This entry is one of 37 documented cases in the AVAAS evidence ledger, a public record of AI and automated-system failures with a verified source on every entry.
Every case here reached a person.
AVAAS certifies how AI systems behave at the decision point, with documented third-party evidence of conformity to a published standard.
Certify Your AI →