Back to skill

Security audit

MetaMask Embedded Wallets (Web3Auth)

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Web3Auth integration skill with no bundled executable code or hidden persistence, though users should handle wallet keys and environment files carefully.

Before installing, confirm you want an agent to consult live MetaMask/Web3Auth docs, MCP tools, and GitHub examples while editing integrations. Treat `.env` values, JWTs, dashboard IDs, and especially exported private keys as sensitive; use user approval for installs and prefer pinned or reviewed package sources when possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The document instructs users to execute npx skills add web3auth/skill without pinning a specific package version or immutable source, which can cause retrieval and execution of whatever package version is current at the time of use. If the package is updated maliciously, compromised upstream, or unexpectedly changed, users could run unreviewed code during a sensitive migration workflow.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/examples.md (reported line 73)May include surrounding context.

md
## React Native (Bare / Expo)

- Built-in EVM and Solana providers which can work with ethers and @solana/web3.js respectively.
- Allowlist bundle ID (iOS) and package name (Android). Deep link scheme must match app config and Dashboard allowlist (`Info.plist`, `AndroidManifest.xml`).
- **Expo Go does not work** — Custom Dev Client or EAS build.
- Metro polyfills differ from web — read RN Metro troubleshooting + `get_example` for RN.
- Hooks is the preferred flow. Imperative `new Web3Auth(...)` works but hooks are preferred.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/platforms.md (reported line 37)May include surrounding context.

md
## React Native (Bare / Expo)

- Built-in EVM and Solana providers which can work with ethers and @solana/web3.js respectively.
- Allowlist bundle ID (iOS) and package name (Android). Deep link scheme must match app config and Dashboard allowlist (`Info.plist`, `AndroidManifest.xml`).
- **Expo Go does not work** — Custom Dev Client or EAS build.
- Metro polyfills differ from web — read RN Metro troubleshooting + `get_example` for RN.
- Hooks is the preferred flow. Imperative `new Web3Auth(...)` works but hooks are preferred.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/platforms.md (reported line 51)May include surrounding context.

md
## React Native (Bare / Expo)

- Built-in EVM and Solana providers which can work with ethers and @solana/web3.js respectively.
- Allowlist bundle ID (iOS) and package name (Android). Deep link scheme must match app config and Dashboard allowlist (`Info.plist`, `AndroidManifest.xml`).
- **Expo Go does not work** — Custom Dev Client or EAS build.
- Metro polyfills differ from web — read RN Metro troubleshooting + `get_example` for RN.
- Hooks is the preferred flow. Imperative `new Web3Auth(...)` works but hooks are preferred.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document normalizes private key export without explicitly warning that exported keys are extremely sensitive and can enable irreversible wallet compromise if logged, transmitted, or stored insecurely. In a developer-facing integration guide, omission of that warning increases the chance that implementers will build unsafe key-handling flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file includes setup steps that create local environment files and populate them with credentials, but it does not warn users that those values may be sensitive or should not be committed or shared. For a setup guide that repeatedly uses .env and client identifiers, a brief disclosure would improve user awareness around credential handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The instructions direct users to create a local .env file and configure identifiers in external dashboards, which can involve sensitive project configuration. The markdown does not include any caution about protecting those values or verifying that the allowlisted identifiers belong to the intended app.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

In the Node.js context, .env files commonly hold real server-side secrets, and the documentation tells users to create one without any warning about secret management or accidental disclosure. Because this is a server-side example family, readers may place private JWT or service credentials there and then leak them via source control or logs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest frames the skill as focused on integrating Web3Auth/Embedded Wallet SDKs and troubleshooting authentication and wallet-address behavior. The private-key export section goes further into general blockchain-usage enablement across platforms, describing when exported keys are the only way to use blockchains, which extends beyond pure integration guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The phrase "New integration" is generic and "any platform" further broadens the scope, making it unclear what qualifies as an eligible invocation. The file does not provide negative examples or boundary conditions to distinguish this scenario from migrations, debugging, or auth-specific work.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file defines scenario headings that function as invocation cues, and "Errors / community issues" is very broad. It does not specify what kinds of errors, products, or contexts qualify, nor does it provide exclusions, increasing the chance of unintended use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.