In a stark warning for users of AI technologies, China's National Computer Network Emergency Response Technical Team (CNCERT) has issued a security alert about the rise of harmful AI agent skills. The advisory, released on Tuesday, details the risks tied to certain skill packages that can enable jailbreaking of AI models and unauthorized cryptocurrency mining, raising serious cybersecurity and legal concerns.
The CNCERT's notice highlights that some of these malicious skills are marketed as tools for "large model jailbreaking" and "crypto-mining for profit." This strategy aims to entice users into bypassing critical security measures of AI models or commandeering device resources for illegal mining activities. Consequently, users could experience various negative outcomes, including account suspensions, reduced device performance, and unintended involvement in illegal activities such as money laundering.
Agent skills are portable packages of instructions and resources that enhance AI agents’ capabilities, but they also present potential security threats. The CNCERT specifically warned that these harmful skills could enable AI models to generate illegal content, posing direct risks to user privacy and the integrity of the platforms involved.
One notable example mentioned by the CNCERT is a skill called "godmode." Marketed as a solution for jailbreaking large models, this skill was found to include advanced attack modules capable of bypassing security measures. Techniques used by this skill involved system prompt replacement and input obfuscation, aimed at tricking AI systems into producing prohibited content, thereby exposing both the user and the platform to serious legal risks.
Beyond jailbreaking, CNCERT also identified skills with built-in cryptocurrency mining functionalities. These packages compel AI agents to download external mining programs, requiring users to dedicate significant computing resources for mining operations. This not only risks economic losses but also legal consequences for unsuspecting participants.
In response to these threats, the CNCERT has urged both individual and enterprise users to implement strict security measures. Individual users are advised to download skills only from official sources, avoid installing packages that claim to enable jailbreaking, and regularly review and revoke sensitive permissions. The advisory also recommends enabling multi-factor authentication to enhance account security.
For enterprise users, the CNCERT suggests implementing a whitelist mechanism for skill admissions, conducting thorough security checks before integrating skills into their systems, and managing agents based on the sensitivity of the data they handle. Isolating agent deployments within secure network environments is also encouraged to reduce potential risks.
As AI technologies continue to advance, the dangers associated with malicious skills highlight the need for vigilance in cybersecurity practices. The CNCERT's advisory serves as a timely reminder of the threats that can emerge from unchecked AI capabilities, particularly as decentralized AI and its applications expand rapidly. Without adequate oversight and security measures, users may face not only legal violations but also significant financial losses.
The implications of this advisory reach beyond China, as similar threats could arise in global AI markets. As the decentralized AI ecosystem grows, it is essential for stakeholders to adopt proactive security protocols to guard against these emerging risks, ensuring a safer environment for users and developers alike.
Quick answers
What are AI agent skills?
AI agent skills are portable packages of instructions that enhance the capabilities of AI agents.
What risks do malicious AI skills pose?
They can enable jailbreaking of AI models and unauthorized cryptocurrency mining, leading to legal and financial repercussions.
How can users protect themselves from these risks?
Users should only download skills from official sources, avoid suspicious packages, and implement multi-factor authentication.
What recommendations does CNCERT give to enterprises?
Enterprises should establish a skills admission whitelist, conduct security checks, and deploy agents in isolated environments.
The stories that move AI & crypto markets — before the market reacts.
Free. 7am ET. Five stories. 62,400 readers.



