MetaMask Agent Wallet
Control a sandboxed MetaMask browser extension wallet for autonomous blockchain transactions. Features configurable permission guardrails including spend limits, chain allowlists, …
Francesco
@andreolf
What This Skill Does
Controls a sandboxed MetaMask browser extension wallet for autonomous blockchain transactions, with configurable permission guardrails like spend limits, chain allowlists, and protocol restrictions.
Replaces manual wallet management for agent-driven DeFi operations by enforcing user-defined constraints on every transaction.
When to Use It
- Execute token swaps on whitelisted DEXes like Uniswap or 1inch
- Send small amounts of ETH or tokens to specified addresses within daily limits
- Connect an agent wallet to a dapp for automated interactions
- Check wallet balances of ETH or specific tokens
- Review recent transaction history and outcomes for audit trails
- Sign messages for on-chain verification or authentication
Install
$ openclaw skills install @andreolf/metamask-agent-wallet-skillMetaMask Agent Wallet Skill
Controls a sandboxed MetaMask wallet for autonomous blockchain transactions with configurable permission guardrails.
Overview
This skill allows AI agents to interact with dapps and execute transactions through a dedicated MetaMask wallet. All operations are subject to user-defined constraints (spend limits, protocol allowlists, approval thresholds).
Security Model: The agent controls a separate wallet in an isolated browser profile. Never use your main wallet.
Setup
1. Install Dependencies
cd metamask-agent-skill
npm install
npx playwright install chromium
2. Create Agent Wallet Profile
npm run setup
This will:
- Create a fresh Chrome profile at
~/.agent-wallet/chrome-profile - Install MetaMask extension
- Guide you through wallet creation (use a NEW seed phrase)
3. Fund the Wallet
Transfer a small amount to your agent wallet:
- ETH for gas (0.01-0.05 ETH recommended)
- Tokens for operations (start small, e.g., $50 USDC)
4. Configure Permissions
Edit permissions.json to set your constraints:
{
"constraints": {
"spendLimit": {
"daily": "50000000", // $50 in 6-decimal format
"perTx": "10000000" // $10 max per transaction
},
"allowedChains": [1, 137, 42161],
"allowedProtocols": ["0x...uniswap", "0x...1inch"]
}
}
Available Actions
Connect to Dapp
connect <dapp-url>
Navigates to dapp and connects the agent wallet.
Example: connect https://app.uniswap.org
Execute Swap
swap <amount> <token-in> for <token-out> [on <dex>]
Executes a token swap on an allowed DEX.
Example: swap 0.01 ETH for USDC on uniswap
Send Tokens
send <amount> <token> to <address>
Sends tokens to an address (within spend limits).
Example: send 10 USDC to 0x1234...
Sign Message
sign <message>
Signs an arbitrary message. Use with caution.
Check Balance
balance [token]
Returns wallet balances.
View Transaction History
history [count]
Shows recent agent transactions with outcomes.
Constraints
All operations check against permissions.json before execution:
| Constraint | Description |
|---|---|
spendLimit.daily | Max USD value per 24h period |
spendLimit.perTx | Max USD value per transaction |
allowedChains | Whitelisted chain IDs |
allowedProtocols | Whitelisted contract addresses |
blockedMethods | Forbidden function selectors |
requireApproval.above | Threshold requiring user confirmation |
Approval Flow
When a transaction exceeds requireApproval.above:
- Agent pauses execution
- Transaction details are logged
- Agent reports: "Transaction requires approval: [details]"
- User must explicitly approve before agent continues
Safety
- Isolated Profile: Agent uses separate Chrome profile, never your main browser
- Separate Wallet: Agent wallet is completely separate from your main wallet
- Spend Caps: Hard limits prevent runaway spending
- Protocol Allowlist: Only whitelisted contracts can be called
- Full Logging: Every transaction intent and outcome is logged
- Revocation: Set
"revoked": truein permissions.json to disable all actions
Logging
All transactions are logged to ~/.agent-wallet/logs/:
{
"timestamp": 1706900000000,
"action": "swap",
"intent": { "to": "0x...", "value": "0", "data": "0x..." },
"guardResult": { "allowed": true },
"outcome": "confirmed",
"txHash": "0x..."
}
Use history command to view recent transactions.
Troubleshooting
"Protocol not allowed"
Add the contract address to allowedProtocols in permissions.json.
"Exceeds daily limit"
Wait 24h or increase spendLimit.daily.
MetaMask popup not detected
Ensure the browser profile path is correct and MetaMask is installed.
Transaction simulation failed
The dapp may be trying to call a blocked method or unsupported chain.
Architecture
src/
├── index.ts # Main entry point
├── browser.ts # Playwright browser management
├── wallet.ts # MetaMask interaction primitives
├── guard.ts # Permission enforcement
├── logger.ts # Transaction logging
├── price.ts # USD price estimation
├── types.ts # TypeScript types
└── config.ts # Configuration loading
Integration with Gator
When Gator accounts are available, permissions.json can be replaced with on-chain permission attestations. The guard will validate against Gator's permission registry instead of local config.
Top skills in this category
Skill Vetter
@spclaudehomeSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Multi Search Engine
@gpyangyoujunMulti search engine integration with 16 engines (7 CN + 9 Global). Supports advanced search operators, time filters, site search, privacy engines, and Wolfra...
Agent Browser
@matrixyHeadless browser automation CLI optimized for AI agents with accessibility tree snapshots and ref-based element selection
Find Skills Skill
@fangkelvinSearch and discover OpenClaw skills from various sources. Use when: user wants to find available skills, search for specific functionality, or discover new s...
Planning with files
@othmanadiManus-style persistent file-based planning for AI coding agents: keeps task_plan.md, findings.md, and progress.md on disk so work survives context loss and /clear. Use when asked to plan out, break down, or organize a multi-step project, research task, or any work requiring 5+ tool calls. Supports a