Back to skill

Security audit

MetaMask Agent Wallet

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for MetaMask wallet automation, but it covers real-money wallet, trading, payment, and plugin actions with some broad or under-scoped guidance that users should review carefully.

Install only if you trust the publisher and intend to let an agent help with real wallet operations. Prefer pinned CLI and skill versions, avoid beast mode and --yes unless you explicitly want unattended execution, never pass mnemonics or passwords on the command line, review every transaction/payment/plugin manifest before approval, and test with small amounts or testnet first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a comprehensive MetaMask/mm CLI skill covering many blockchain and payment-related operations. The supplied code does none of that: it simply parses two command-line arguments, scales an amount by token decimals using Decimal, converts the result to an integer, and prints the hexadecimal representation. While this utility is loosely related to one narrow declared topic ('decoding EVM calldata' or token utilities), its primary purpose is materially narrower and different from the declared single-entry-point mm CLI behavior. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description substantially overstates the skill's scope. The supplied code only supports x402-related workflows: inspecting HTTP 402/x402 payment requirements, paying a selected x402 option over HTTP, parsing MCP x402 payment challenges, and signing a payment payload for MCP retries. It uses mm only as a dependency for chain lookup, wallet address retrieval, token metadata lookup, and EIP-712 typed-data signing. There is no code for balances, swaps, bridges, futures, prediction markets, calldata decoding, plugin installation/removal, authentication, or broad mm CLI command routing. The x402-related portion of the description is accurate, but the claim that this is the single entry point for all mm CLI operations is materially inaccurate versus the actual code behavior.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

md
For approval surfaces and recovery steps, see [troubleshooting.md](workflows/troubleshooting.md).

## Output Rules

- Route silently. Do not announce which reference you are loading.
- Surface errors from commands verbatim. Do not mask or reword them.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly expects powerful capabilities including file reads, network access, and shell execution, but it does not declare an explicit tool scope or permission boundary. That makes the trust model ambiguous and increases the risk that an agent platform may expose broader capabilities than intended, especially for a skill that can trigger wallet operations, plugin management, and external requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is extremely broad and can match many unrelated wallet, trading, payment, plugin, and blockchain contexts. Over-broad routing can cause unintended invocation of a highly privileged skill, increasing the chance of unsafe shell/network actions or wallet-affecting workflows being loaded when a narrower, safer skill would suffice.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The instruction to re-install skills with npx skills add metaMask/agent-skills references an unpinned package/tool resolution path, which can pull whatever version is current at execution time. In supply-chain terms, this creates a moving target and increases exposure to compromised or incompatible upstream releases.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The skill explicitly permits some auth and wallet-management actions to execute without confirmation. In a wallet/authentication context, even seemingly administrative actions can change session state, expose account metadata, log users out, alter configuration, or prepare the environment for later sensitive actions without a clear user checkpoint.

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

md
| Cancel-all operations | Always confirm scope and exact destructive effect before executing |
| Wallet policy changes | Broadening policy changes require MFA approval; non-broadening changes apply immediately |
| Trading mode changes | Broadening from guard to beast requires MFA approval. Tightening from beast to guard applies immediately |
| Auth / wallet management | May execute without confirmation, except `reset` which requires explicit user confirmation |
| Read-only queries | May execute without confirmation |

### Credential Safety

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

Allowing read-only queries without confirmation is generally acceptable, but in this context some 'read-only' operations may still expose sensitive wallet, account, transaction, or environment information to the agent or logs. The danger is lower than for write actions, yet the broad scope of this skill makes silent data exposure more consequential.

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
| Wallet policy changes | Broadening policy changes require MFA approval; non-broadening changes apply immediately |
| Trading mode changes | Broadening from guard to beast requires MFA approval. Tightening from beast to guard applies immediately |
| Auth / wallet management | May execute without confirmation, except `reset` which requires explicit user confirmation |
| Read-only queries | May execute without confirmation |

### Credential Safety

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples explicitly show secrets passed as command-line arguments, such as --new "mypassword" and similar password flags. Command-line secrets can be exposed through shell history, process listings, logging, CI job traces, and terminal scrollback, which is especially risky in a wallet/authentication context where the password protects a BYOK mnemonic and could lead to wallet compromise if recovered.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The documentation instructs users to use npx skills add without pinning a specific package version, which can pull whatever version is current at execution time. If the upstream package, dependency chain, or resolution source is compromised or unexpectedly changed, users could install and run unreviewed code in a high-trust local agent/plugin context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This example again references npx skills add as an installation path without version pinning, creating a supply-chain risk through execution of the latest resolved package version. In a wallet-related skill ecosystem, that risk is amplified because installed skills may influence sensitive operations, authentication flows, and payment-enabled tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation presents cross-chain deposits and automatic ERC-20 approvals as routine behavior but does not clearly warn that these actions can move assets across networks and grant spending permissions to third-party contracts. In a wallet/DeFi skill, that omission increases the chance that an agent or user initiates irreversible fund movement or overly broad approvals without informed confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The --all withdrawal option enables complete withdrawal of a position, yet the documentation does not emphasize that this can trigger full fund movement, possible slippage/fees, or irreversible state changes once signed. In the context of an agent wallet skill, missing cautionary language makes accidental full-balance withdrawals more likely, especially if commands are composed or executed automatically from user prompts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/errors.md (reported line 152)May include surrounding context.

md
| `RWA_GEO_RESTRICTED` | RWA asset not available in your region |
| `RWA_NATIVE_TOKEN_UNSUPPORTED` | RWA cannot be swapped against native asset |
| `RWA_MARKET_UNAVAILABLE` | RWA market temporarily unavailable |
| `QUOTE_PERSIST_FAILED` | Failed to persist the quote to `~/.metamask/swap-quotes/`. The CLI already retries a transient directory-creation failure once, so this means the path is genuinely unwritable. Create it manually with `mkdir -p ~/.metamask/swap-quotes && chmod 700 ~/.metamask/swap-quotes`, then re-run `mm swap quote` |
| `QUOTE_NOT_FOUND` | Quote not found |
| `EXECUTE_FAILED` | Swap execution failed. When the job is paused on MFA and no hash is available yet, the message names the wait and `mm wallet requests watch` — treat as an MFA pause, not a missing hash |
| `NO_TRADE_DATA` | No trade data available |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This documentation describes state-changing deposit, withdraw, and transfer operations as effectively non-interactive while defaulting to mainnet, which increases the chance an agent or user will move real funds without an explicit safety checkpoint. In a wallet/trading skill, unclear guidance around non-prompting financial actions materially raises the risk of unintended asset movement, especially because this skill is a single entry point for wallet operations and may be invoked autonomously.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/plugins.md (reported line 139)May include surrounding context.

md
An approved install writes a record under `plugins` in `~/.metamask/config.json`. The record holds `version`, `integrity`, `manifestHash`, `approvedCapabilities`, `approvedCommandIds`, and `approvedAt`.

A fresh consent prompt appears whenever the version or the manifest hash changes, including on `mm plugins update`. Until the new manifest is approved, the plugin's commands run with zero capabilities, and any call that needs one fails with `PERMISSION_DENIED`. The same downgrade applies when no approval record exists, and when the command id is missing from `approvedCommandIds`.

When a plugin command returns `PERMISSION_DENIED`, do not retry it. Run `mm plugins install <pkg>` or `mm plugins update <pkg>` so the user can approve the current manifest, then run the command again.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/plugins.md (reported line 149)May include surrounding context.

mm plugins uninstall @acme/mm-report

text

This removes the plugin code and deletes its approval record from `~/.metamask/config.json`. It is not beta gated and shows no consent prompt, so it still works after `experimentalPlugins` is set back to `false`. The argument is the installed package name, with or without a version or dist tag suffix.

Reset removes everything the user installed or linked.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This documentation describes commands that can place trades, move funds, withdraw assets, and redeem positions, but it does not consistently foreground that these actions can cause real financial loss, may be irreversible, and may execute on mainnet depending on the current mode. In an agent skill context, omission of explicit safety warnings increases the chance an autonomous or semi-autonomous agent invokes high-impact commands without adequate user confirmation or risk disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation presents --yes as a normal option for mm swap quote and even includes an example, but it does not prominently warn that this can proceed directly to an on-chain swap or bridge without an interactive confirmation step. In a wallet/asset-transfer skill, that omission is dangerous because an agent or user may treat a quote as read-only and accidentally authorize irreversible fund movement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This documentation teaches users how to broadcast raw EVM transactions but omits an explicit warning that on-chain transactions are typically irreversible and may transfer real value. In a wallet skill whose purpose is sending transactions, that omission increases the chance of accidental loss, mistaken signing, or unsafe use of arbitrary calldata, especially by less experienced users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The transfer documentation omits an explicit warning that blockchain transfers are generally irreversible and that mistakes in recipient address, chain ID, or token selection can permanently lose funds. In the context of a wallet agent that serves as a single entry point for transfers and payments, missing this warning increases the chance that users or agents execute high-stakes transactions without adequate confirmation safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation exposes a high-risk beast mode that explicitly skips wallet policy checks, but it does not provide a prominent warning about the security consequences of doing so. In an agent-operated wallet context, this can normalize or encourage unsafe configurations that weaken outflow and whitelist protections, increasing the chance of unauthorized or high-risk transactions being approved.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/x402.md (reported line 75)May include surrounding context.

md
calls at the caller. A local idempotency ledger is a possible future addition.

Examples:
    python3 x402_pay.py inspect https://api.example.com/premium
    python3 x402_pay.py pay https://api.example.com/premium --confirm
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/x402.md (reported line 77)May include surrounding context.

md
calls at the caller. A local idempotency ledger is a possible future addition.

Examples:
    python3 x402_pay.py inspect https://api.example.com/premium
    python3 x402_pay.py pay https://api.example.com/premium --confirm
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/x402_pay.py (reported line 51)May include surrounding context.

python
calls at the caller. A local idempotency ledger is a possible future addition.

Examples:
    python3 x402_pay.py inspect https://api.example.com/premium
    python3 x402_pay.py pay https://api.example.com/premium --confirm
"""

Static analysis

No suspicious patterns detected.