Help AI coding agents integrate MetaMask Embedded Wallets (Web3Auth) SDKs.
Do not connect
The assessed surface is high-risk. Remediate the findings before connecting.
Scanned 29 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The web3auth-embedded-wallets MCP server exposes 5 tools, focused primarily on general-purpose capabilities. Its published description reads: "Help AI coding agents integrate MetaMask Embedded Wallets (Web3Auth) SDKs". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates web3auth-embedded-wallets D- — the assessed surface is high-risk and should be remediated before use. Its most notable findings include "Data-exfiltration parameters" and "No authorization on a public remote server". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check web3auth-embedded-wallets's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add web3auth-embedded-wallets to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.web3auth.ioStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Search MetaMask Embedded Wallets documentation (Algolia) and example projects. Returns doc page links with snippets and matching examples.
Fetch the full content of a MetaMask Embedded Wallets documentation page by URL. Sources: Algolia, llms.txt, GitHub MDX.
Fetch complete source code of a Web3Auth integration example from GitHub.
Fetch SDK source code (types, interfaces, hooks) from open-source Web3Auth repos.
Search or fetch posts from the MetaMask Embedded Wallets community forum (builder.metamask.io).
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: get_doc
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: search_docs
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_doc
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_example
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: get_sdk_reference
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: search_community
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Validates up to 75,000 URLs per job checking status codes, redirects, and response times.
Pay-per-call AI API marketplace with 47 endpoints — OCR, TTS, LLM chat, image generation, weather, and crypto pricing — paid via x402 USDC micropayments on Base.
EPA drinking water quality data in plain English, providing AI agents with tap water quality information for US cities via nine public-data tools.
AI phone answering and appointment booking tools for service businesses.
Aggregates Romanian TV, streaming, cinema, and theater listings for AI agents.
Agent-callable Parallax services — catalog browsing, pricing, project start, and booking.